Candidate: CVE-2013-0245 PublicDate: 2013-07-16 18:55:00 UTC References: https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2013-0245 http://www.openwall.com/lists/oss-security/2013/01/30 http://drupal.org/SA-CORE-2013-001 Description: The printer friendly version functionality in the Book module in Drupal 6.x before 6.28 and 7.x before 7.19 does not properly restrict access to node that are part of a book outline, which allows remote authenticated users with the "access printer-friendly version" permission to read node titles and possibly node content via unspecified vectors. Ubuntu-Description: Notes: Bugs: Priority: medium Discovered-by: Assigned-to: CVSS: Patches_drupal6: upstream_drupal6: released (6.28) hardy_drupal6: DNE lucid_drupal6: ignored (reached end-of-life) oneiric_drupal6: ignored (reached end-of-life) precise_drupal6: ignored (reached end-of-life) precise/esm_drupal6: DNE (precise was needed) quantal_drupal6: ignored (reached end-of-life) raring_drupal6: ignored (reached end-of-life) saucy_drupal6: DNE trusty_drupal6: DNE trusty/esm_drupal6: DNE utopic_drupal6: DNE vivid_drupal6: DNE vivid/stable-phone-overlay_drupal6: DNE vivid/ubuntu-core_drupal6: DNE wily_drupal6: DNE xenial_drupal6: DNE yakkety_drupal6: DNE zesty_drupal6: DNE devel_drupal6: DNE Patches_drupal7: upstream_drupal7: released (7.19) hardy_drupal7: DNE lucid_drupal7: DNE oneiric_drupal7: DNE precise_drupal7: ignored (reached end-of-life) precise/esm_drupal7: DNE (precise was needed) quantal_drupal7: ignored (reached end-of-life) raring_drupal7: not-affected (7.22-1) saucy_drupal7: not-affected (7.22-1) trusty_drupal7: not-affected (7.22-1) trusty/esm_drupal7: DNE (trusty was not-affected [7.22-1]) utopic_drupal7: not-affected (7.22-1) vivid_drupal7: not-affected (7.22-1) vivid/stable-phone-overlay_drupal7: DNE vivid/ubuntu-core_drupal7: DNE wily_drupal7: not-affected (7.22-1) xenial_drupal7: not-affected (7.22-1) yakkety_drupal7: not-affected (7.22-1) zesty_drupal7: not-affected (7.22-1) devel_drupal7: not-affected (7.22-1)