The User module in Drupal 6.x before 6.38 and 7.x before 7.43 allows remote attackers to gain privileges by leveraging contributed or custom code that calls the user_save function with an explicit category and loads all roles into the array.
| Name | Vendor | Start Version | End Version |
|---|---|---|---|
| Debian_linux | Debian | 7.0 (including) | 7.0 (including) |
| Debian_linux | Debian | 8.0 (including) | 8.0 (including) |
| Drupal6 | Ubuntu | precise | * |
| Drupal6 | Ubuntu | upstream | * |
| Drupal7 | Ubuntu | artful | * |
| Drupal7 | Ubuntu | esm-infra-legacy/trusty | * |
| Drupal7 | Ubuntu | precise | * |
| Drupal7 | Ubuntu | trusty | * |
| Drupal7 | Ubuntu | trusty/esm | * |
| Drupal7 | Ubuntu | upstream | * |
| Drupal7 | Ubuntu | wily | * |
| Drupal7 | Ubuntu | yakkety | * |
| Drupal7 | Ubuntu | zesty | * |