Vulnerable Systems:
* Drupal Announcements 6.x-1.x versions prior to 6.x-1.5.
The Announcements module creates an "announcement" content type and provides both node views and block lists.The module doesn't sufficiently check node access under certain conditions.This vulnerability is mitigated by the fact that an attacker must have a role with the permission "access announcements".