The Drupal project uses the PEAR Archive_Tar library, which had released a security update that impacts Drupal.

The vulnerability is mitigated by the fact that Drupal core’s use of the Archive_Tar library is not vulnerable, as it does not permit symlinks. On the other hand, exploitation was possible if contribution or custom code used the library to extract tar archives (for example .tar, .tar.gz, .bz2, or .tlz) which come from a potentially untrusted source.

This vulnerability affects the following application versions:

  • Drupal 7.69
  • Drupal 7.70
  • Drupal 7.71
  • Drupal 7.72
  • Drupal 7.73
  • Drupal 7.74
  • Drupal 7.75
  • Drupal 7.76
  • Drupal 7.77
  • Drupal 7.78
  • Drupal 7.79
  • Drupal 7.80
  • Drupal 7.81

Skriv et svar

Din e-mailadresse vil ikke blive publiceret. Krævede felter er markeret med *