The Memcache module 5.x before 5.x-1.10 and 6.x before 6.x-1.6 for Drupal does not properly handle the $user object in memcache_admin, which might "lead to a role change not being recognized until the user logs in again."
Weaknesses in this category are related to the management of permissions, privileges, and other security features that are used to perform access control.
Link | Tags |
---|---|
http://secunia.com/advisories/41663 | third party advisory vendor advisory |
http://drupal.org/node/927016 | patch vendor advisory |
http://drupal.org/node/926478 | patch |
http://www.vupen.com/english/advisories/2010/2543 | vdb entry |