
=====================================================================

                           CERT-Renater

               Note d'Information No. 2013/VULN485
_____________________________________________________________________

DATE                : 24/10/2013

HARDWARE PLATFORM(S): /

OPERATING SYSTEM(S):  Systems running Spaces for DRUPAL versions
                                6.x-3.x prior to 6.x-3.7.

======================================================================
https://drupal.org/node/2118717
______________________________________________________________________

SA-CONTRIB-2013-081 - Spaces - Access bypass
Posted by Drupal Security Team on October 23, 2013 at 4:00pm


    Advisory ID: DRUPAL-SA-CONTRIB-2013-081
    Project: Spaces (third-party module)
    Version: 6.x
    Date: 2013-10-23
    Security risk: Less critical
    Exploitable from: Remote
    Vulnerability: Access bypass


Description

This module enables you to make configuration options generally
available only at the sitewide level to be configurable and overridden
by individual "spaces" on a Drupal site.

The spaces submodule, Spaces OG, doesn't properly handle deleting of
organic group group spaces when the option to move to a new group is
selected. Instead of moving the content to a new group, the content is
left orphaned, and for deleted private groups, that content will then
be viewable by anyone with "access content" permission when the site's
or content's access is rebuilt.

The issue is mitigated by needing to be using the submodule spaces OG,
and needing the site users to be in the situation of deleting a group
and using that move option, and needing the content's access to be
rebuilt.

CVE identifier(s) issued

    A CVE identifier will be requested, and added upon issuance, in
accordance with Drupal Security Team processes.


Versions affected

    Spaces 6.x-3.x versions prior to 6.x-3.7.

Drupal core is not affected. If you do not use the contributed Spaces
module, there is nothing you need to do.


Solution

Install the latest version:

    If you use the Spaces module for Drupal 6.x, upgrade to Spaces
6.x-3.7

Also see the Spaces project page.


Reported by

    Hunter Fox of the Drupal Security Team


Fixed by

    Tobby Hagler a module maintainer
    Hunter Fox of the Drupal Security Team, module maintainer.


Coordinated by

    Hunter Fox of the Drupal Security Team


Contact and More Information

The Drupal security team can be reached at security at drupal.org or
via the contact form at http://drupal.org/contact.

Learn more about the Drupal Security team and their policies, writing
secure code for Drupal, and securing your site.


Categories: Drupal 6.x


=========================================================
Serveur de référence du CERT-Renater
https://services.renater.fr/ssi/
==========================================================
+ CERT-RENATER          | tel : 01-53-94-20-44           +
+ 23 - 25 Rue Daviel    | fax : 01-53-94-20-41           +
+ 75013 Paris           | email: cert@support.renater.fr +
==========================================================
