CVE-2013-4502: Medium severity Nathan Haug Filefield Sources vulnerability
Published May 13, 2014
·Updated
The FileField Sources module 6.x-1.x before 6.x-1.9 and 7.x-1.x before 7.x-1.9 for Drupal does not properly check file permissions, which allows remote authenticated users to read arbitrary files by attaching a file.
Affected Software
37 affected components
Nathan Haug Filefield Sources=7.x-1.2-beta1
Nathan Haug Filefield Sources=7.x-1.3
Nathan Haug Filefield Sources=7.x-1.4
Nathan Haug Filefield Sources=7.x-1.5
Nathan Haug Filefield Sources=7.x-1.6
Nathan Haug Filefield Sources=7.x-1.7
Nathan Haug Filefield Sources=7.x-1.8
Nathan Haug Filefield Sources=7.x-1.x-dev
Drupal Drupal
Nathan Haug Filefield Sources=6.x-1.0
Nathan Haug Filefield Sources=6.x-1.1
Nathan Haug Filefield Sources=6.x-1.2
Nathan Haug Filefield Sources=6.x-1.3
Nathan Haug Filefield Sources=6.x-1.4
Nathan Haug Filefield Sources=6.x-1.5
Nathan Haug Filefield Sources=6.x-1.6
Nathan Haug Filefield Sources=6.x-1.7
Nathan Haug Filefield Sources=6.x-1.8
All of the following
Any of the following
Nathan Haug Filefield Sources=7.x-1.2-beta1
Nathan Haug Filefield Sources=7.x-1.3
Nathan Haug Filefield Sources=7.x-1.4
Nathan Haug Filefield Sources=7.x-1.5
Nathan Haug Filefield Sources=7.x-1.6
Nathan Haug Filefield Sources=7.x-1.7
Nathan Haug Filefield Sources=7.x-1.8
Nathan Haug Filefield Sources=7.x-1.x-dev
Drupal Drupal
All of the following
Any of the following
Nathan Haug Filefield Sources=6.x-1.0
Nathan Haug Filefield Sources=6.x-1.1
Nathan Haug Filefield Sources=6.x-1.2
Nathan Haug Filefield Sources=6.x-1.3
Nathan Haug Filefield Sources=6.x-1.4
Nathan Haug Filefield Sources=6.x-1.5
Nathan Haug Filefield Sources=6.x-1.6
Nathan Haug Filefield Sources=6.x-1.7
Nathan Haug Filefield Sources=6.x-1.8
Drupal Drupal
Remediation
Patch Available
Patch Available
Patch Available
Event History
May 13, 2014
CVE Published
via MITRE·03:00 PM
Data Sourced
via MITRE·03:00 PM
Description
Data Sourced
via NVD·03:55 PM
RemedyDescriptionSeverityWeaknessAffected Software
Frequently Asked Questions
1
What is the severity of CVE-2013-4502?
CVE-2013-4502 has a moderate severity rating due to improper file permission checks.
2
How do I fix CVE-2013-4502?
To fix CVE-2013-4502, update the FileField Sources module to version 6.x-1.9 or 7.x-1.9 or later.
3
Who is affected by CVE-2013-4502?
CVE-2013-4502 affects users of the FileField Sources module for Drupal versions before 6.x-1.9 and 7.x-1.9.
4
What exploit does CVE-2013-4502 enable?
CVE-2013-4502 enables remote authenticated users to read arbitrary files on the server.
5
Is CVE-2013-4502 specific to any Drupal version?
Yes, CVE-2013-4502 is specific to certain older versions of the FileField Sources module for both Drupal 6 and 7.