First published: Mon Oct 01 2012(Updated: )
The image module in Drupal 7.x before 7.14 does not properly check permissions when caching derivative image styles of private images, which allows remote attackers to read private image styles.
Credit: secalert@redhat.com
Affected Software | Affected Version | How to fix |
---|---|---|
Drupal Drupal | =7.0 | |
Drupal Drupal | =7.0-alpha1 | |
Drupal Drupal | =7.0-alpha2 | |
Drupal Drupal | =7.0-alpha3 | |
Drupal Drupal | =7.0-alpha4 | |
Drupal Drupal | =7.0-alpha5 | |
Drupal Drupal | =7.0-alpha6 | |
Drupal Drupal | =7.0-alpha7 | |
Drupal Drupal | =7.0-beta1 | |
Drupal Drupal | =7.0-beta2 | |
Drupal Drupal | =7.0-beta3 | |
Drupal Drupal | =7.0-dev | |
Drupal Drupal | =7.0-rc1 | |
Drupal Drupal | =7.0-rc2 | |
Drupal Drupal | =7.0-rc3 | |
Drupal Drupal | =7.0-rc4 | |
Drupal Drupal | =7.1 | |
Drupal Drupal | =7.2 | |
Drupal Drupal | =7.3 | |
Drupal Drupal | =7.4 | |
Drupal Drupal | =7.5 | |
Drupal Drupal | =7.6 | |
Drupal Drupal | =7.7 | |
Drupal Drupal | =7.8 | |
Drupal Drupal | =7.9 | |
Drupal Drupal | =7.10 | |
Drupal Drupal | =7.11 | |
Drupal Drupal | =7.12 | |
Drupal Drupal | =7.13 | |
Drupal Drupal | =7.x-dev |
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
CVE-2012-1591 is classified as a moderate severity vulnerability.
To fix CVE-2012-1591, upgrade your Drupal installation to version 7.14 or later.
CVE-2012-1591 allows remote attackers to read private image styles by exploiting improper permission checks.
CVE-2012-1591 affects Drupal 7.x before version 7.14.
No, CVE-2012-1591 is specifically present in Drupal 7.x versions prior to 7.14.