Debian Security Advisory
DLA-2721-1 drupal7 -- LTS security update
- Date Reported:
- 26 Jul 2021
- Affected Packages:
- drupal7
- Vulnerable:
- Yes
- Security database references:
- In Mitre's CVE dictionary: CVE-2021-32610.
- More information:
-
The Drupal project uses the pear Archive_Tar library, which has released a security update that impacts Drupal.
The vulnerability is mitigated by the fact that Drupal core's use of the Archive_Tar library is not vulnerable, as it does not permit symlinks.
Exploitation may be possible if contrib or custom code uses the library to extract tar archives (for example .tar, .tar.gz, .bz2, or .tlz) which come from a potentially untrusted source.
For Debian 9 stretch, this problem has been fixed in version 7.52-2+deb9u16.
We recommend that you upgrade your drupal7 packages.
For the detailed security status of drupal7 please refer to its security tracker page at: https://security-tracker.debian.org/tracker/drupal7
Further information about Debian LTS security advisories, how to apply these updates to your system and frequently asked questions can be found at: https://wiki.debian.org/LTS
--u3/rZRmxL6MmkK24 Content-Type: application/pgp-signature; name="signature.asc"