-----BEGIN PGP SIGNED MESSAGE----- Hash: SHA256 Format: 1.8 Date: Mon, 11 Jul 2016 20:18:44 +0200 Source: drupal7 Binary: drupal7 Architecture: source all Version: 7.14-2+deb7u13 Distribution: wheezy-security Urgency: high Maintainer: Luigi Gangitano <luigi@debian.org> Changed-By: Chris Lamb <lamby@debian.org> Description: drupal7 - fully-featured content management framework Changes: drupal7 (7.14-2+deb7u13) wheezy-security; urgency=high . * CVE-2015-7943: The "Overlay" module in Drupal core displays administrative pages as a layer over the current page (using JavaScript) rather than replacing the page in the browser window. The module did not sufficiently validate URLs prior to displaying their contents, leading to an open redirect vulnerability. Checksums-Sha1: 815b7998d38eed5ba58ac829eb4ca7f2198944e8 1836 drupal7_7.14-2+deb7u13.dsc ab33bea454fed20c535e37a71cea6004599488c3 3128473 drupal7_7.14.orig.tar.gz 63e2ed11f515dc3495b6e5aa4e00c5adcd42018f 251707 drupal7_7.14-2+deb7u13.debian.tar.gz 6fdc48c6e004b3ad894c504b7010113e97d30746 3198678 drupal7_7.14-2+deb7u13_all.deb Checksums-Sha256: c47f9357c48bb99a8aa29bdd14692fc0668736086173aed60e5114ceabc20b2e 1836 drupal7_7.14-2+deb7u13.dsc 17db094aaa78d76ec6a3517171f1d8c158745eee2e19006d5ed97b7ffc2c54da 3128473 drupal7_7.14.orig.tar.gz 4dc6e59bc3e5b4c0186c8e1938d135b691d61f5fe6a390e5df0f122145b2ea20 251707 drupal7_7.14-2+deb7u13.debian.tar.gz e4784990854b4e62980fc87aed7d85345aacc63466cf4bf77e5db3d4bb4c80aa 3198678 drupal7_7.14-2+deb7u13_all.deb Files: f796437d0f439a648838303be91ea2d1 1836 web extra drupal7_7.14-2+deb7u13.dsc af7abd95c03ecad4e1567ed94a438334 3128473 web extra drupal7_7.14.orig.tar.gz 8fc9c2549d5da7191bea952035f6ff0e 251707 web extra drupal7_7.14-2+deb7u13.debian.tar.gz a6cc8ace7555f83702bf39f7d135718b 3198678 web extra drupal7_7.14-2+deb7u13_all.deb -----BEGIN PGP SIGNATURE----- Version: GnuPG v1 iQIcBAEBCAAGBQJXg+UlAAoJEB6VPifUMR5YXbkP/3jLHdIk9PCI5prhejb8yZzO kBrTR5+kpzMW8z/sxsunSX6f4tOJVi4yj4kqqGSFGsFuMLa6sqDGTsiLrkdFu2V7 8JQM2cS9Jdw0BlAfMkadNvha+QkuAhyt2Q7WMzT+3n/wzU0jQDA23Y1bysVpgnSq du6SBVyk70elOZWM38932Ohp+6y2F9sQ6BRczqPzYvD3+Rz6S2dGs/O4Bsv6WiGS BAtjn10dRT8xQf7mwJUvWoGT9L6n61eHdOHMSO+/lHpx6J6j0m7MZA4CbBl9zw0d y1RhvSiFicF0514KQxmnsZZ3Z4G5YC7d23DbY5mw/ND1f5gxtqrR/Vq9wjMM5V08 7LbTrRmt7n0SwcmbAaBk4TuK3oY5BGGh3Yum3JCTDBQ1m0Kz3xLBr39hA5DqTThU CkWL1LCWN0SEHsJdWOKe4O1Lty75P1E1YEmMdfEHyTklFV+n1Jtad8tGCtb6AYws +DQONVdFEhRYzBKlZkPggoHge2S8FMn95i87Ghh3VVWV26kCwQ7PhlH9MD3q8VNr jYvMTCTV/+aev/0y9qk6YRwG1x4Ss+bzeb6yatwp8F//owliR7mgwi2FwzNs2rUf NxnYxIs1NNSXvr2WtpOqLNZGy9TMKYLEW0rRJG+UAz1GNuok3D6U36r3pPl34WdH Kgnb6188SPOrOUsW6hGK =xrYo -----END PGP SIGNATURE-----