[安全公告]SA-2007-022: Boost - file overwrite

由 Evance 于 周日, 2007-10-14 09:39 提交。

来源:布拉格公园 :源文

drupal这几天的补丁发得倒是刷刷的.....

公告序列: DRUPAL-SA-2007-022.

Project : boost (第三方模组)

版 本 : 4.7.x-1.*, 5.x-0.* (这一个貌似比上一个影响大一些..)

日  期 : 2007-10-03 (汗...刚才看了一下,邮件是4号发的,但是为什么我今天才收到呢?)

风险级别: 严重

可利用隐患:远程

全文:
------------SA-2007-022 - BOOST - FILE OVERWRITE------------

* Advisory ID: DRUPAL-SA-2007-022.

* Project: Boost (third-party module)

* Version: 4.7.x-1.*, 5.x-0.*

* Date: 2007-10-03

* Security risk: Critical

* Exploitable from: Remote

* Vulnerability: Filesystem overwrite

------------DESCRIPTION------------

The Boost [ http://drupal.org//project/boost ] module provides a static
file-based cache of Drupal pages for anonymous users. A vulnerability allows an
attacker to create or overwrite any filename in any directory that the web
server can write to. The affected file will always contain the fully rendered
HTML for a single Drupal page; the attacker cannot control the content of the
affected file in any other way.

As an example, since most Drupal web servers have write access to the Drupal
installation directory, the attacker could replace Drupal's index.php with the
HTML of another page from the same site of his choosing, causing /every/ page
from the attacked site to appear like the chosen page.

------------VERSIONS AFFECTED------------

* 5.x:

* Boost before version 5.x-1.0

* 4.7.x:

* Boost before version 4.7.x-1.0

Drupal core is not affected. If you do not use the contributed Boost module,
there is nothing you need to do.

------------SOLUTION------------

Install the latest version:

* 5.x:

* Boost 5.x-1.0 [ http://drupal.org//node/179811 ]

* 4.7.x:

* Boost 4.7.x-1.0 [ http://drupal.org//node/179810 ]

------------REPORTED BY------------

Barry Jaspan [ http://drupal.org/user/46413 ] of the Drupal security team.

------------CONTACT------------

The security contact for Drupal can be reached at security at drupal.org or via
the form at [ http://drupal.org/contact ].

这模块不错啊。。。

这模块不错啊。。。适合国内行情。。。
群上那些叫着drupal没有静态生成的人没话了吧