Debian Security Advisory
DLA-1550-1 drupal7 -- LTS security update
- Date Reported:
- 19 Oct 2018
- Affected Packages:
- drupal7
- Vulnerable:
- Yes
- Security database references:
- No other external database security references currently available.
- More information:
-
It was discovered that there was a remote code execution and an external URL injection vulnerability in the Drupal content management framework.
For more information, please see:
https://www.drupal.org/sa-core-2018-006
For Debian 8
Jessie
, these issues have been fixed in drupal7 version 7.32-1+deb8u13.We recommend that you upgrade your drupal7 packages.