CVE-2016-3170

NameCVE-2016-3170
DescriptionThe "have you forgotten your password" links in the User module in Drupal 7.x before 7.43 and 8.x before 8.0.4 allow remote attackers to obtain sensitive username information by leveraging a configuration that permits using an email address to login and a module that permits logging in.
SourceCVE (at NVD; CERT, LWN, oss-sec, fulldisc, Red Hat, Ubuntu, Gentoo, SUSE bugzilla/CVE, GitHub advisories/code/issues, web search, more)
ReferencesDSA-3498-1
Debian Bugs756305

Vulnerable and fixed packages

The table below lists information on source packages.

Source PackageReleaseVersionStatus
drupal7 (PTS)jessie, jessie (lts)7.32-1+deb8u19fixed
stretch (security), stretch (lts), stretch7.52-2+deb9u18fixed

The information below is based on the following data on fixed versions.

PackageTypeReleaseFixed VersionUrgencyOriginDebian Bugs
drupal6source(unstable)(not affected)
drupal7sourcewheezy7.14-2+deb7u12DSA-3498-1
drupal7sourcejessie7.32-1+deb8u6DSA-3498-1
drupal7source(unstable)7.43-1
drupal8ITP756305

Notes

- drupal6 <not-affected> (Only affects Drupal 7.x and Drupal 8.x)
https://www.drupal.org/SA-CORE-2016-001
https://www.openwall.com/lists/oss-security/2016/02/24/19

Search for package or bug name: Reporting problems