Software Update: Drupal 7.62 / 8.5.9 / 8.6.6

Spread the love

Updates have been released for versions 7, 8.5 and 8.6 from Drupal, which should fix various vulnerabilities. Drupal is a PHP-written, user-friendly and powerful content management platform, with which, for example, websites can be created. It’s simple enough for a novice user, but powerful enough to build a more complex website as well. The program includes a content management platform and a development framework. Advisory SA-CORE-2019-001 reports fixing a vulnerability in the PEAR Archive_Tar library.

security risk:
Critical 16∕25 AC:Complex/A:User/CI:All/II:All/E:Proof/TD:Uncommon

Vulnerability:
Third Party Libraries

Description:

Drupal core uses the third-party PEAR Archive_Tar library. This library has released a security update which impacts some Drupal configurations. refer to CVE-2018-1000888 for details.

Solution:

  • If you are using Drupal 8.6.x, upgrade to Drupal 8.6.6.
  • If you are using Drupal 8.5.x or earlier, upgrade to Drupal 8.5.9.
  • If you are using Drupal 7.x, upgrade to Drupal 7.62.

Versions of Drupal 8 prior to 8.5.x are end-of-life and do not receive security coverage.

Version number 7.62 / 8.5.9 / 8.6.6
Release status Final
Operating systems script language
Website Drupal
Download
License type GPL
You might also like