-----BEGIN PGP SIGNED MESSAGE----- Hash: SHA256 Format: 1.8 Date: Fri, 15 Jul 2016 09:35:17 +0200 Source: drupal7 Binary: drupal7 Architecture: source all Version: 7.14-2+deb7u14 Distribution: wheezy-security Urgency: high Maintainer: Luigi Gangitano <luigi@debian.org> Changed-By: Chris Lamb <lamby@debian.org> Description: drupal7 - fully-featured content management framework Changes: drupal7 (7.14-2+deb7u14) wheezy-security; urgency=high . * CVE-2016-6211: A vulnerability existed in the User module, where if some specific contributed or custom code triggers a rebuild of the user profile form, a registered user can be granted all user roles on the site. This would typically result in the user gaining administrative access. Checksums-Sha1: 0cb76a765bf8cadc964fe6b6d1b65e93d19d2f1a 1836 drupal7_7.14-2+deb7u14.dsc ab33bea454fed20c535e37a71cea6004599488c3 3128473 drupal7_7.14.orig.tar.gz ac3d9efb3a1eaf3bce098e1ccc5a5788e5e304f2 252180 drupal7_7.14-2+deb7u14.debian.tar.gz 1deb57d0002d5636559e0fbc41e7935fb0956a33 3198632 drupal7_7.14-2+deb7u14_all.deb Checksums-Sha256: dba7b1c3266f816c0bac1cd3189648232e123f6184846f5db8ff234d8678d8ea 1836 drupal7_7.14-2+deb7u14.dsc 17db094aaa78d76ec6a3517171f1d8c158745eee2e19006d5ed97b7ffc2c54da 3128473 drupal7_7.14.orig.tar.gz 2b30e3cd3854aa07bad16d214c69301e68c08bc10b086ee02a1d95c8bac83fd8 252180 drupal7_7.14-2+deb7u14.debian.tar.gz 3a16ff1685b0da6efc1ee204535670fce5a98baa06e97c92517a8c88f1b75124 3198632 drupal7_7.14-2+deb7u14_all.deb Files: 8c46469ad5cc62c1af668b8e7b39c0db 1836 web extra drupal7_7.14-2+deb7u14.dsc af7abd95c03ecad4e1567ed94a438334 3128473 web extra drupal7_7.14.orig.tar.gz c6f868c230865318a0dbd2a192e3ac0e 252180 web extra drupal7_7.14-2+deb7u14.debian.tar.gz be8c21bd5bb1f20350d6e0f0805d546c 3198632 web extra drupal7_7.14-2+deb7u14_all.deb -----BEGIN PGP SIGNATURE----- Version: GnuPG v1 iQIcBAEBCAAGBQJXiJUjAAoJEB6VPifUMR5Y6MYP/00vSQdWUsmr4D/XHGUbnp6R MG5L1MPCC0p769S0ce6i/I4GImfXifDv3jBe320J+h+TqfNVY4t4fsaUxft1xdno iDRT288fXmuvdKY6GIUJiCBwUeC8jTQLYxVhfHeSLbSp0VDiEfhVo0SqOjUbqGnN RblCY6zIypnwUxAtLlsTcvVkDR52IUfAnrMnUhmcpP5J0x3hH8bic0nEht5BvfH/ dvxX7EM0xx9Qy/4tsVf9HfJtHm+j9lfIAyNFxE1eKsNdnqb1nkbG7IfgVzUBif6N 2BA6G4/+TkXmeO9MEZLVV5b0NiB0Lkq1HtE6Aib9kcW2xaQTzYBI+UKK8QGFSbJd LHOQG0gil6foP9DwmScLOaD2yQ7Cgj8v5ERefHReYVwF4QJN6tSoNAXXl8665DTX okvTrLAw5+QFSl854oVTT2tNYjdMtWCVwLExOyyX3HW5YHasFdFK0fMtDzLORZ2Y G9FEoY8iqToCiXlcpfdqpV6dz76TtZJCk2lQyaU5r42+SvmByh5W3iH1l/k1QFHI MuMy5QwrjnQluIv7PIfZu4d5aprMqrIecv0hiLQ1Ah4a4WrxMnJ8EW4iJxGKgTBf Wa6RPAhVlNMgAjjyo/RECVVQi5ahK0oPXksIVlZugDrdTkmEFPujqQHAqxtkh2cQ MEHu63wCV1pIt2TWfWtF =8zUZ -----END PGP SIGNATURE-----