The upload module looked up files for download in the database and serves them for download after access checking. However, it did not account for the fact that certain database configurations would not consider case differences in file names. If a malicious user uploaded a file which only differs in letter case, access would be granted for the earlier upload regardless of actual file access to that.
Part of security release SA-CORE-2010-002
This vulnerability affects the following application versions:
- Drupal 6.0
- Drupal 6.1
- Drupal 6.2
- Drupal 6.3
- Drupal 6.4
- Drupal 6.5
- Drupal 6.6
- Drupal 6.7
- Drupal 6.8
- Drupal 6.9
- Drupal 6.10
- Drupal 6.11
- Drupal 6.12
- Drupal 6.13
- Drupal 6.14
- Drupal 6.15
- Drupal 6.16
- Drupal 6.17