CVE Vulnerabilities

CVE-2013-0246

Published: Jul 16, 2013 | Modified: Nov 21, 2024
CVSS 3.x
N/A
Source:
NVD
CVSS 2.x
4.3 MEDIUM
AV:N/AC:M/Au:N/C:P/I:N/A:N
RedHat/V2
RedHat/V3
Ubuntu
MEDIUM

The Image module in Drupal 7.x before 7.19, when a private file system is used, does not properly restrict access to derivative images, which allows remote attackers to read derivative images of otherwise restricted images via unspecified vectors.

Affected Software

Name Vendor Start Version End Version
Drupal Drupal 7.0 (including) 7.0 (including)
Drupal Drupal 7.0-alpha1 (including) 7.0-alpha1 (including)
Drupal Drupal 7.0-alpha2 (including) 7.0-alpha2 (including)
Drupal Drupal 7.0-alpha3 (including) 7.0-alpha3 (including)
Drupal Drupal 7.0-alpha4 (including) 7.0-alpha4 (including)
Drupal Drupal 7.0-alpha5 (including) 7.0-alpha5 (including)
Drupal Drupal 7.0-alpha6 (including) 7.0-alpha6 (including)
Drupal Drupal 7.0-alpha7 (including) 7.0-alpha7 (including)
Drupal Drupal 7.0-beta1 (including) 7.0-beta1 (including)
Drupal Drupal 7.0-beta2 (including) 7.0-beta2 (including)
Drupal Drupal 7.0-beta3 (including) 7.0-beta3 (including)
Drupal Drupal 7.0-dev (including) 7.0-dev (including)
Drupal Drupal 7.0-rc1 (including) 7.0-rc1 (including)
Drupal Drupal 7.0-rc2 (including) 7.0-rc2 (including)
Drupal Drupal 7.0-rc3 (including) 7.0-rc3 (including)
Drupal Drupal 7.0-rc4 (including) 7.0-rc4 (including)
Drupal Drupal 7.1 (including) 7.1 (including)
Drupal Drupal 7.2 (including) 7.2 (including)
Drupal Drupal 7.3 (including) 7.3 (including)
Drupal Drupal 7.4 (including) 7.4 (including)
Drupal Drupal 7.5 (including) 7.5 (including)
Drupal Drupal 7.6 (including) 7.6 (including)
Drupal Drupal 7.7 (including) 7.7 (including)
Drupal Drupal 7.8 (including) 7.8 (including)
Drupal Drupal 7.9 (including) 7.9 (including)
Drupal Drupal 7.10 (including) 7.10 (including)
Drupal Drupal 7.11 (including) 7.11 (including)
Drupal Drupal 7.12 (including) 7.12 (including)
Drupal Drupal 7.13 (including) 7.13 (including)
Drupal Drupal 7.14 (including) 7.14 (including)
Drupal Drupal 7.15 (including) 7.15 (including)
Drupal Drupal 7.16 (including) 7.16 (including)
Drupal Drupal 7.17 (including) 7.17 (including)
Drupal Drupal 7.18 (including) 7.18 (including)
Drupal Drupal 7.x-dev (including) 7.x-dev (including)
Drupal6 Ubuntu lucid *
Drupal6 Ubuntu oneiric *
Drupal6 Ubuntu precise *
Drupal6 Ubuntu quantal *
Drupal6 Ubuntu raring *
Drupal6 Ubuntu upstream *
Drupal7 Ubuntu precise *
Drupal7 Ubuntu quantal *
Drupal7 Ubuntu upstream *

References