lists.openwall.net   lists  /  announce  owl-users  owl-dev  john-users  john-dev  passwdqc-users  yescrypt  popa3d-users  /  oss-security  kernel-hardening  musl  sabotage  tlsify  passwords  /  crypt-dev  xvendor  /  Bugtraq  Full-Disclosure  linux-kernel  linux-netdev  linux-ext4  PHC 
Open Source and information security mailing list archives
 
Hash Suite: Windows password security audit tool. GUI, reports in PDF.
[<prev] [next>] [day] [month] [year] [list]
Date: Thu, 17 Jan 2019 21:43:27 +0000
From: Moritz Muehlenhoff <jmm@...ian.org>
To: bugtraq@...urityfocus.com
Subject: [SECURITY] [DSA 4370-1] drupal7 security update

-----BEGIN PGP SIGNED MESSAGE-----
Hash: SHA512

- -------------------------------------------------------------------------
Debian Security Advisory DSA-4370-1                   security@...ian.org
https://www.debian.org/security/                       Moritz Muehlenhoff
January 17, 2019                      https://www.debian.org/security/faq
- -------------------------------------------------------------------------

Package        : drupal7
CVE ID         : not yet available

Two vulnerabilities were found in Drupal, a fully-featured content
management framework, which could result in arbitrary code execution.

For additional information, please refer to the upstream advisories
at https://www.drupal.org/sa-core-2019-001 and
https://www.drupal.org/sa-core-2019-002

For the stable distribution (stretch), this problem has been fixed in
version 7.52-2+deb9u6.

We recommend that you upgrade your drupal7 packages.

For the detailed security status of drupal7 please refer to
its security tracker page at:
https://security-tracker.debian.org/tracker/drupal7

Further information about Debian Security Advisories, how to apply
these updates to your system and frequently asked questions can be
found at: https://www.debian.org/security/

Mailing list: debian-security-announce@...ts.debian.org
-----BEGIN PGP SIGNATURE-----

iQIzBAEBCgAdFiEEtuYvPRKsOElcDakFEMKTtsN8TjYFAlxA9lIACgkQEMKTtsN8
TjbEeRAAjW1a55CuIHGncKgjHfEalKe4YMS6zfe7pEve+eRtHSVKL01OXMknq9dl
BW4VohFccb3HBcuRNfRT6x1NZ2NZL92rps7FlCiAi7omqk2q4NcqhUBNlXyHlOqN
QDoEg076vSeZTvnfk1ageY5ya6fFy2TI2LHPIaojycKuy9uNFklfUVPYbMSbdzxQ
KBo6r3XQRVzP55de7UreXDuwqcSL4FRHTP4FTH/geaZhp8ls26y9ZBegXCvCLfjk
AmigYRMpkA8Z8nwJoJLnG1bAL+kZk+PTQVhVeit1FVNEsnaaivp89IjDNCo/3jMu
uIGzCHyApJ3DAqgekZQmxwCPWKvd7gT0LOS1owDZjrKp8sKDwP7VKolodqfYipqo
Y42ox13B/W7sHQi9ACWRX8Yc3+lgsr143TX4aoMN67VxFuLGxyZUHgMFlpIhBp1w
TDClHB1Tom94oqVo3dfTnBUQaExFbh/tgIC/JGl9qZt450typ9z+8B2fFWxOAw0Q
H4kMd/+NfRgWMsDbiSCovkKiDTHdh/Q4bMOFdVTPlaAtpCj/WK1eS3jKIWDg4UXQ
hmYdR9OGyL8dMEs+YUp9aGQqtRs5LcPAed9YoADXqOc9wJevy7tdpEN9V5/zwutJ
T1Yoivfk6sIGaJpSU6xBitx+/M0IqQfQjYI+oX1TPa6Rw6vYkFE=
=90ur
-----END PGP SIGNATURE-----

Powered by blists - more mailing lists