Debian Security Advisory
DSA-2983-1 drupal7 -- security update
- Date Reported:
- 20 Jul 2014
- Affected Packages:
- drupal7
- Vulnerable:
- Yes
- Security database references:
- In the Debian bugtracking system: Bug 755038.
In Mitre's CVE dictionary: CVE-2014-5019, CVE-2014-5020, CVE-2014-5021, CVE-2014-5022. - More information:
-
Multiple security issues have been discovered in the Drupal content management system, ranging from denial of service to cross-site scripting. More information can be found at https://www.drupal.org/SA-CORE-2014-003.
For the stable distribution (wheezy), this problem has been fixed in version 7.14-2+deb7u5.
For the testing distribution (jessie), this problem has been fixed in version 7.29-1.
For the unstable distribution (sid), this problem has been fixed in version 7.29-1.
We recommend that you upgrade your drupal7 packages.