Forum archive
Drupal 6.13 fixes Multiple vulnerabilities
First, thanks for building these appliances. I have a Turnkey LAMP appliance installed at VPS.Net and it is working well.
I'm about to create a new VPS for Drupal 6. I noticed on the appliance page that the current Drupal 6 appliance is at Drupal release 6.12. Unfortunately, 6.12 suffers from Cross-site scripting, Input format access bypass, and Password leaked in URL vulnerabilities.
Release 6.13 from July 1 fixes these. Please consider upgrading the Turnkey Appliance to run Drupal 6.13. I'm hoping to start my new VPS on this release.
Thanks for considering this upgrade,
-Dan
Thanks for the nudge. We're in the middle of a development cycle so things are a bit busy at the moment.
From the changelog it seems that the Debian Security Team opted not to upgrade the Debian package to 6.13 but rather backport the XSS fix to 6.12-1. The patched version is 6.12-1.1 and thats what we should be putting into our security repository. I'll talk to Alon about that today.