[Date Prev][Date Next] [Thread Prev][Thread Next] [Date Index] [Thread Index]

[SECURITY] [DLA 1797-1] drupal7 security update



-----BEGIN PGP SIGNED MESSAGE-----
Hash: SHA512

Package        : drupal7
Version        : 7.32-1+deb8u17
CVE ID         : CVE-2019-11358 CVE-2019-11831
Debian Bug     : 927330 928688

Several security vulnerabilities have been discovered in drupal7, a
PHP web site platform. The vulnerabilities affect the embedded versions
of the jQuery JavaScript library and the Typo3 Phar Stream Wrapper
library.

CVE-2019-11358

    It was discovered that the jQuery version embedded in Drupal was
    prone to a cross site scripting vulnerability in jQuery.extend().

    For additional information, please refer to the upstream advisory
    at https://www.drupal.org/sa-core-2019-006.

CVE-2019-11831

    It was discovered that incomplete validation in a Phar processing
    library embedded in Drupal, a fully-featured content management
    framework, could result in information disclosure.

    For additional information, please refer to the upstream advisory
    at https://www.drupal.org/sa-core-2019-007.

For Debian 8 "Jessie", these problems have been fixed in version
7.32-1+deb8u17.

We recommend that you upgrade your drupal7 packages.

Further information about Debian LTS security advisories, how to apply
these updates to your system and frequently asked questions can be
found at: https://wiki.debian.org/LTS


- -- 
Jonas Meurer


-----BEGIN PGP SIGNATURE-----

iQIzBAEBCgAdFiEELIzSg9Pv30M4kOeDUmLn/0kQSf4FAlzit/4ACgkQUmLn/0kQ
Sf7Vnw/+MlRUrgDnbKvlAERr6TDph9kcSwl9rbi4kElY3vj0xQZGnaX2HZGYyHHT
uUr9xp3JY6UyLrWQLiBmPdtRKTF2dHkTpEna9lrn8JXXMpZsKohkpEmotBfiG4E5
FdkAZtVwcn+4FrnLSvkJrxn9U8huokwEYypSk7lj2OUtXJu1qpYO5pGcRpCGH3Bn
3U3IaAwf+zZvB118GzgBJThbkOMvhIHWLE55E6aUx7navEw87blyvnv/t+f8yEzB
wiGVL3sIyxpZau2k3pvMm36ytplP5rD/1UpvyB7Vvqv1uu/1E/+8GdpuishUqSVO
T2xiwjIAzAqP1SiJzXWx103poNlhHPFAj8Z/xFqybs/HfMgIEFK60oulZYDRBXo8
+gQ+dH10oM14Qrfgyiwa+TydkSsGqAg5rDN5m1Uj5ncNcRQeQ+vCDoiJefTid/55
KPTkswqgUoZReIDTZ0q0f902gjgpp8uOsuJZUwvrjM8neI6pMm3scJqrns8K5K2B
TyNTvtWc/muhhYeB3si9vXM8Ou6uvb2MG+8UT2WqEd4L1VCo7ty46CQSx+h0XHJt
BeVbhQEJKYAUCR0W0Wrbux9gV3Z5R054YuIGklUreirmw4vqsDZ+Xf+EexRetWNH
DdQIuUVSv2UQ7juqTdgsGbEz7JgnUw5wp+eSjuQ1gHvJ7q387GQ=
=LBM6
-----END PGP SIGNATURE-----


Reply to: