Lucene search

K
drupalDrupal Security TeamDRUPAL-SA-CONTRIB-2012-026
HistoryFeb 29, 2012 - 12:00 a.m.

SA-CONTRIB-2012-026 - ZipCart - Access bypass

2012-02-2900:00:00
Drupal Security Team
www.drupal.org
6

6 Medium

CVSS2

Attack Vector

NETWORK

Attack Complexity

MEDIUM

Authentication

SINGLE

Confidentiality Impact

PARTIAL

Integrity Impact

PARTIAL

Availability Impact

PARTIAL

AV:N/AC:M/Au:S/C:P/I:P/A:P

0.967 High

EPSS

Percentile

99.7%

CVE: CVE-2012-1650

ZipCart enables a site to provide users with Zip archives for downloads selected by the user.

Versions of ZipCart prior to 6.x-1.4 checks an incorrect permission when building archives. This vulnerability is mitigated by the fact that archive file addition is only permitted if Drupal’s normal file download access check permits the user to download the file directly.

Versions affected

  • ZipCart 6.x versions prior to 6.x-1.4.

Drupal core is not affected. If you do not use the contributed ZipCart module, there is nothing you need to do.

Solution

Install the latest version:

See also the ZipCart project page.

Reported by

Fixed by

Coordinated by

6 Medium

CVSS2

Attack Vector

NETWORK

Attack Complexity

MEDIUM

Authentication

SINGLE

Confidentiality Impact

PARTIAL

Integrity Impact

PARTIAL

Availability Impact

PARTIAL

AV:N/AC:M/Au:S/C:P/I:P/A:P

0.967 High

EPSS

Percentile

99.7%

Related for DRUPAL-SA-CONTRIB-2012-026