CVE-2012-1591 on Ubuntu 12.04 LTS (precise) - medium.
Description:
The image module in Drupal 7.x before 7.14 does not properly check permissions when caching derivative image styles of private images, which allows remote attackers to read private image styles.