FS#42388 - [drupal] Security release on Wednesday, October 15 (NY time)

Attached to Project: Community Packages
Opened by Remi Gacogne (rgacogne) - Wednesday, 15 October 2014, 12:24 GMT
Last edited by Sergej Pupykin (sergej) - Thursday, 16 October 2014, 09:05 GMT
Task Type Bug Report
Category Packages
Status Closed
Assigned To Sergej Pupykin (sergej)
Architecture All
Severity High
Priority Normal
Reported Version
Due in Version Undecided
Due Date Undecided
Percent Complete 100%
Votes 0
Private No



Just to give a head start, Drupal announced a security release for Drupal 7 for Wednesday, October 15:

This task depends upon

Closed by  Sergej Pupykin (sergej)
Thursday, 16 October 2014, 09:05 GMT
Reason for closing:  Fixed
Comment by Remi Gacogne (rgacogne) - Wednesday, 15 October 2014, 16:29 GMT

"Drupal 7 includes a database abstraction API to ensure that queries executed against the database are sanitized to prevent SQL injection attacks.

A vulnerability in this API allows an attacker to send specially crafted requests resulting in arbitrary SQL execution. Depending on the content of the requests this can lead to privilege escalation, arbitrary PHP execution, or other attacks."