https:// https:// https:// https:// https://. -------------------------------------------------------------------------------- Fedora Update Notification FEDORA-2025-f8a08bb335 2025-11-29 17:02:16.261291+00:00 -------------------------------------------------------------------------------- Name : drupal7 Product : Fedora 42 Version : 7.103 Release : 1.fc42 URL : https:// Summary : An open-source content-management platform Description : Equipped with a powerful blend of features, Drupal is a Content Management System written in PHP that can support a variety of websites ranging from personal weblogs to large community-driven websites. Drupal is highly configurable, skinnable, and secure. -------------------------------------------------------------------------------- Update Information: https:// https:// https:// https:// https:// https:// https:// -------------------------------------------------------------------------------- ChangeLog: * Wed Nov 19 2025 Shawn Iwinski - 7.103-1 - Update to 7.103 (RHBZ #2253220) - SA-CORE-2024-005 / CVE-2024-55635 - SA-CORE-2024-008 / CVE-2024-55638 * Wed Jul 23 2025 Fedora Release Engineering - 7.98-7 - Rebuilt for https://fedoraproject.org/wiki/Fedora_43_Mass_Rebuild -------------------------------------------------------------------------------- References: [ 1 ] Bug #2253220 - drupal7-7.103 is available https://bugzilla.redhat.com/show_bug.cgi?id=2253220 -------------------------------------------------------------------------------- This update can be installed with the "dnf" update program. Use su -c 'dnf upgrade --advisory FEDORA-2025-f8a08bb335' at the command line. For more information, refer to the dnf documentation available at http://dnf.readthedocs.io/en/latest/command_ref.html#upgrade-command-label All packages are signed with the Fedora Project GPG key. More details on the GPG keys used by the Fedora Project can be foundat https://fedoraproject.org/keys -------------------------------------------------------------------------------- -- _______________________________________________ package-announce mailing list --
Two security vulnerabilities have been discovered in Wordpress, a popular content management framework, a PHP File Upload bypass via the plugin installer and a possible remote code execution vulnerability which requires an attacker to control all the properties of a deserialized object. No CVE have . ------------------------------------------------------------------------- Debian LTS Advisory DLA-3756-1
- [7.98]() - [7.97]() - [7.96]() - [SA- CORE-2023-005]() - [7.95]() - [SA-. -------------------------------------------------------------------------------- Fedora Update Notification FEDORA-2023-83aeb73043 2023-10-04 15:47:53.759443 -------------------------------------------------------------------------------- Name : drupal7 Product : Fedora 37 Version : 7.98 Release : 1.fc37 URL : Summary : An open-source content-management platform Description : Equipped with a powerful blend of features, Drupal is a Content Management System written in PHP that can support a variety of websites ranging from personal weblogs to large community-driven websites. Drupal is highly configurable, skinnable, and secure. -------------------------------------------------------------------------------- Update Information: - [7.98]() - [7.97]() - [7.96]() - [SA- CORE-2023-005]() - [7.95]() - [SA- CORE-2023-004]() - [7.94]() - [7.93]() -------------------------------------------------------------------------------- ChangeLog: * Tue Sep 26 2023 Shawn Iwinski - 7.98-1 - Update to 7.98 (RHBZ #2217253) - SA-CORE-2023-004 - SA-CORE-2023-005 (RHBZ #2188106, 2188107, 2188108) * Wed Jul 19 2023 Fedora Release Engineering - 7.92-3 - Rebuilt for https://fedoraproject.org/wiki/Fedora_39_Mass_Rebuild * Thu Jan 19 2023 Fedora Release Engineering - 7.92-2 - Rebuilt for https://fedoraproject.org/wiki/Fedora_38_Mass_Rebuild -------------------------------------------------------------------------------- References: [ 1 ] Bug #2188107 - drupal7: drupal: File download facility doesn't sufficiently sanitize file paths [fedora-all] https://bugzilla.redhat.com/show_bug.cgi?id=2188107 [ 2 ] Bug #2188108 - drupal7: drupal: File download facility doesn't sufficiently sanitize file paths [epel-7] https://bugzilla.redhat.com/show_bug.cgi?id=2188108 [ 3 ] Bug #2217253 - drupal7-7.98 is available https://bugzilla.redhat.com/show_bug.cgi?id=2217253 -------------------------------------------------------------------------------- This update can be installed with the "dnf" update program. Use su -c 'dnf upgrade --advisory FEDORA-2023-83aeb73043' at the command line. For more information, refer to the dnf documentation available at https://dnf.readthedocs.io/en/latest/command_ref.html All packages are signed with the Fedora Project GPG key. More details on the GPG keys used by the Fedora Project can be found at https://fedoraproject.org/security/ -------------------------------------------------------------------------------- _______________________________________________ package-announce mailing list --
- [7.92]() - [7.91]() - [SA-CORE-2022-012 / CVE-2022-25275]() - [7.90]() - [7.89]() -. --------------------------------------------------------------------------------Fedora Update Notification FEDORA-2022-c4334d5277 2022-11-10 22:04:44.630660 --------------------------------------------------------------------------------Name : drupal7 Product : Fedora 37 Version : 7.92 Release : 1.fc37 URL : Summary : An open-source content-management platform Description : Equipped with a powerful blend of features, Drupal is a Content Management System written in PHP that can support a variety of websites ranging from personal weblogs to large community-driven websites. Drupal is highly configurable, skinnable, and secure. --------------------------------------------------------------------------------Update Information: - [7.92]() -[7.91]() - [SA-CORE-2022-012 / CVE-2022-25275]() -[7.90]() -[7.89]() -[7.88]() - [SA-CORE-2022-003 / CVE-2022-25271]() -[7.87]() -[7.86]() - [SA-CORE-2022-001 / CVE-2021-41184]() -[SA-CORE-2022-002 / CVE-2021-41182 / CVE-2021-41183 / CVE-2016-7103 / CVE-2010-5312]() -[7.85]() -[7.84]() -[7.83]() --------------------------------------------------------------------------------ChangeLog: * Sat Oct 15 2022 Shawn Iwinski - 7.92-1 - Update to 7.92 - SA-CORE-2022-012 / CVE-2022-25275 - SA-CORE-2022-003 / CVE-2022-25271 (RHBZ #2055472, 2055473) - SA-CORE-2022-001 / CVE-2021-41184 - SA-CORE-2022-002 / CVE-2021-41182 / CVE-2021-41183 --------------------------------------------------------------------------------References: [ 1 ] Bug #2055472 - CVE-2022-25271 drupal7: drupal: improper input validation found via drupal core api [epel-all] https://bugzilla.redhat.com/show_bug.cgi?id=2055472 [ 2 ] Bug #2055473 - CVE-2022-25271 drupal7: drupal: improper input validation found via drupal core api [fedora-all] https://bugzilla.redhat.com/show_bug.cgi?id=2055473 --------------------------------------------------------------------------------This update can be installed with the "dnf" update program. Use su -c 'dnf upgrade --advisory FEDORA-2022-c4334d5277' at the command line. For more information, refer to the dnf documentation available at https://dnf.readthedocs.io/en/latest/command_ref.html All packages are signed with the Fedora Project GPG key. More details on the GPG keys used by the Fedora Project can be found at https://fedoraproject.org/security/ --------------------------------------------------------------------------------_______________________________________________ package-announce mailing list --
- - - - . --------------------------------------------------------------------------------Fedora Update Notification FEDORA-2020-7d8f772540 2020-11-27 01:20:50.553240 --------------------------------------------------------------------------------Name : drupal7 Product : Fedora 33 Version : 7.74 Release : 1.fc33 URL : Summary : An open-source content-management platform Description : Equipped with a powerful blend of features, Drupal is a Content Management System written in PHP that can support a variety of websites ranging from personal weblogs to large community-driven websites. Drupal is highly configurable, skinnable, and secure. --------------------------------------------------------------------------------Update Information: - - - - --------------------------------------------------------------------------------ChangeLog: * Wed Nov 18 2020 Shawn Iwinski - 7.74-1 - Update to 7.74 - SA-CORE-2020-007 / CVE-2020-13666 - SA-CORE-2020-012 / CVE-2020-13671 --------------------------------------------------------------------------------This update can be installed with the "dnf" update program. Use su -c 'dnf upgrade --advisory FEDORA-2020-7d8f772540' at the command line. For more information, refer to the dnf documentation available at https://dnf.readthedocs.io/en/latest/command_ref.html All packages are signed with the Fedora Project GPG key. More details on the GPG keys used by the Fedora Project can be found at https://fedoraproject.org/security/ --------------------------------------------------------------------------------_______________________________________________ package-announce mailing list --
Several vulnerabilities were discovered in Drupal, a fully-featured content management framework, which could result in an open redirect or cross-site scripting. . -----BEGIN PGP SIGNED MESSAGE----- Hash: SHA512 - ------------------------------------------------------------------------- Debian Security Advisory DSA-4693-1
An input sanitization bypass was discovered in Wordpress, a popular content management framework. An attacker can use this flaw to send malicious scripts to an unsuspecting user. . Package : wordpress Version : 4.1.29+dfsg-0+deb8u1 CVE ID : CVE-2019-20041 Debian Bug : 946905 An input sanitization bypass was discovered in Wordpress, a popular content management framework. An attacker can use this flaw to send malicious scripts to an unsuspecting user. For Debian 8 "Jessie", this problem has been fixed in version 4.1.29+dfsg-0+deb8u1. We recommend that you upgrade your wordpress packages. Further information about Debian LTS security advisories, how to apply these updates to your system and frequently asked questions can be found at: https://wiki.debian.org/LTS . Enhance your Wordpress installations in Debian 8 to address a vulnerability in input validation that permits harmful scripts.. Wordpress Security, Debian LTS, Input Sanitization Issue, Content Management, Security Update. . LinuxSecurity.com Team
- - [SA-CORE-2019-007]() ([CVE-2019-11831](https://nvd.nist.gov/vuln/detail/CVE-2019-11831)). --------------------------------------------------------------------------------Fedora Update Notification FEDORA-2019-040857fd75 2019-05-25 03:34:29.628857 --------------------------------------------------------------------------------Name : drupal7 Product : Fedora 29 Version : 7.67 Release : 1.fc29 URL : Summary : An open-source content-management platform Description : Equipped with a powerful blend of features, Drupal is a Content Management System written in PHP that can support a variety of websites ranging from personal weblogs to large community-driven websites. Drupal is highly configurable, skinnable, and secure. --------------------------------------------------------------------------------Update Information: - - [SA-CORE-2019-007]() ([CVE-2019-11831](https://nvd.nist.gov/vuln/detail/CVE-2019-11831)) --------------------------------------------------------------------------------ChangeLog: * Wed May 15 2019 Shawn Iwinski - 7.67-1 - Update to 7.67 (RHBZ #1707958, #1708649, #1708652, #1708653) - (CVE-2019-11831) * Tue Apr 30 2019 Shawn Iwinski - 7.66-1 - Update to 7.66 (RHBZ #1701036, #1702424, #1702425, #1702620, #1702619) - (CVE-2019-11358) * Wed Mar 20 2019 Shawn Iwinski - 7.65-1 - Update to 7.65 (RHBZ #1691035) - * Sat Feb 23 2019 Shawn Iwinski - 7.64-1 - Update to 7.64 (RHBZ #1673206) - - * Thu Jan 31 2019 Fedora Release Engineering - 7.60-3 - Rebuilt for https://fedoraproject.org/wiki/Fedora_30_Mass_Rebuild * Sun Oct 28 2018 Shawn Iwinski - 7.60-2 - Explicit python dependencies - Explicit python2 except el5 - See https://koji.fedoraproject.org/koji/buildinfo?buildID=1156502 * Sat Oct 27 2018 Shawn Iwinski - 7.60-1 - Update to 7.60 (RHBZ #1643121 / RHBZ #1643122 / RHBZ #1643124 / SA-CORE-2018-006) - Remove patch drupal-7.14-CVE-2012-2922 (see) --------------------------------------------------------------------------------References: [ 1 ] Bug #1707958 - drupal7-7.67 is available https://bugzilla.redhat.com/show_bug.cgi?id=1707958 --------------------------------------------------------------------------------This update can be installed with the "dnf" update program. Use su -c 'dnf upgrade --advisory FEDORA-2019-040857fd75' at the command line. For more information, refer to the dnf documentation available at https://dnf.readthedocs.io/en/latest/command_ref.html All packages are signed with the Fedora Project GPG key. More details on the GPG keys used by the Fedora Project can be found at https://fedoraproject.org/security/ --------------------------------------------------------------------------------_______________________________________________ package-announce mailing list --
Get the latest Linux and open source security news straight to your inbox.