Ubuntu Security Update USN-6981-2: Drupal vulnerabilities

LinuxBot

Member
Joined
Apr 25, 2017
Messages
5,863
Reaction score
74
Credits
-1,257
USN-6981-1 fixed vulnerabilities in Drupal. This update provides the corresponding updates for Ubuntu 14.04 LTS. Original advisory details: It was discovered that Drupal incorrectly sanitized uploaded filenames. A remote attacker could possibly use this issue to execute arbitrary code. (CVE-2020-13671) It was discovered that Drupal incorrectly sanitized archived filenames. A remote attacker could possibly use this issue to overwrite arbitrary files, or execute arbitrary code. (CVE-2020-28948, CVE-2020-28949)

Continue reading...
 


Follow Linux.org

Staff online


Latest posts

Top