UBUNTU-CVE-2015-7943
Dashboard / Vulnerabilities / UBUNTU-CVE-2015-7943
Summary:
Details: Open redirect vulnerability in the Overlay module in Drupal 7.x before 7.41, the jQuery Update module 7.x-2.x before 7.x-2.7 for Drupal, and the LABjs module 7.x-1.x before 7.x-1.8 allows remote attackers to redirect users to arbitrary web sites and conduct phishing attacks via unspecified vectors. NOTE: this vulnerability exists because of an incomplete fix for CVE-2015-3233.
References: https://ubuntu.com/security/CVE-2015-7943, https://www.drupal.org/SA-CORE-2015-004, http://www.openwall.com/lists/oss-security/2015/10/21/6, https://www.cve.org/CVERecord?id=CVE-2015-7943
Affected packages
Package
Name: drupal7
Purl: pkg:deb/ubuntu/[email protected]+esm3?arch=source&distro=esm-infra-legacy/trusty
Affected ranges
Type: ECOSYSTEM
Events:
