NavigationUser login |
[Security announcements] Textimage - response validation bypass![]() And of course... We already updated... ------------TEXTIMAGE - RESPONSE VALIDATION BYPASS------------ * Advisory ID: DRUPAL-SA-2007-007 * Project: Textimage (third-party module) * Version: 4.7.x, 5.x * Date: 2007-Jan-31 * Security risk: Less critical * Exploitable from: Remote * Vulnerability: Captcha bypass ------------DESCRIPTION------------ Captcha validation by Textimage can be bypassed by manipulating request ------------VERSIONS AFFECTED------------ * All versions of Textimage 4.7.x prior to Textimage 4.7-1.2. * All versions of Textimage 5.x prior to Textimage 5.x-1.1. Drupal core is not affected. If you do not use the contributed Captcha module, ------------SOLUTION------------ Install the latest version: * If you use Drupal 4.7.x use Textimage 4.7.x-1.2 * If you use Drupal 5.x use Textimage 5.x-1.1 See also the Textimage project page [http://drupal.org/project/textimage]. Thomas Nilsson. ------------CONTACT------------ The security contact for Drupal can be reached at security at drupal.org or via |
Similar entriesBloggersWho's new
Who's onlineThere are currently 3 users and 44 guests online.
Online users
SearchRecent blog posts
|