SA-CONTRIB-2016-024 marked EPSA Crop as insecure for an unfixed vulnerability in the Drupal 7 version. However, the EPSA Crop module has a Drupal 6 branch which could be affected by the same vulnerability.

At this time, none of the Drupal 6 Long-Term Support vendors are supporting the this module (ie. none of their paying customers use it), so the vendors haven't ported the fix and won't unless they start supporting the module later (ie. if a customer who uses the module signs up).

This issue is a placeholder for if one of the vendors or a community member want to port the fix to Drupal 6.

Comments

dsnopek created an issue.

mlhess’s picture

We would need to wait before we had a public patch of this. If an LTS vendor wanted to take this over, I would propose they take ownership of the module as well and fix it for 7.x