Package        : drupal7
Version        : 7.32-1+deb8u15
CVE ID         : CVE-2019-6338


Drupal core uses the third-party PEAR Archive_Tar library. This
library has released a security update which impacts some Drupal
configurations. Refer to CVE-2018-1000888 for details. Also a possible
regression caused by CVE-2019-6339 is fixed.

For Debian 8 "Jessie", this problem has been fixed in version
7.32-1+deb8u15.

We recommend that you upgrade your drupal7 packages.

Further information about Debian LTS security advisories, how to apply
these updates to your system and frequently asked questions can be
found at: https://wiki.debian.org/LTS

Debian LTS: DLA-1685-1: drupal7 security update

February 20, 2019
Drupal core uses the third-party PEAR Archive_Tar library

Summary

For Debian 8 "Jessie", this problem has been fixed in version
7.32-1+deb8u15.

We recommend that you upgrade your drupal7 packages.

Further information about Debian LTS security advisories, how to apply
these updates to your system and frequently asked questions can be
found at: https://wiki.debian.org/LTS


Severity
Package : drupal7
Version : 7.32-1+deb8u15
CVE ID : CVE-2019-6338

Related News