Audit Linux privileges now to limit compromise, escalation, and system-wide damage. Review Linux Privileges×
Several security issues were fixed in Drupal.. ========================================================================== Ubuntu Security Notice USN-7658-1 July 21, 2025 drupal7 vulnerabilities ========================================================================== A security issue affects these releases of Ubuntu and its derivatives: - Ubuntu 16.04 LTS - Ubuntu 14.04 LTS Summary: Several security issues were fixed in Drupal. Software Description: - drupal7: fully-featured content management framework Details: It was discovered that Drupal incorrectly parsed untrusted HTML. A remote attacker could possibly use this issue to execute arbitrary code. Update instructions: The problem can be corrected by updating your system to the following package versions: Ubuntu 16.04 LTS drupal7 7.44-1ubuntu1~16.04.0+esm3 Available with Ubuntu Pro Ubuntu 14.04 LTS drupal7 7.26-1ubuntu0.1+esm3 Available with Ubuntu Pro In general, a standard system update will make all the necessary changes. References: https://ubuntu.com/security/notices/USN-7658-1 CVE-2020-11022, CVE-2020-11023 . Multiple vulnerabilities resolved in WordPress for Ubuntu 20.04 and 18.04 LTS. Upgrade today to safeguard your platforms!. Ubuntu Security, Drupal 7 Issues, Remote Code Execution, Security Updates, Drupal Vulnerabilities. . Severity: Important. LinuxSecurity.com Team
Drupal could be made to crash or run programs if it received specially crafted network traffic.. ========================================================================== Ubuntu Security Notice USN-6981-1 August 27, 2024 drupal7 vulnerabilities ========================================================================== A security issue affects these releases of Ubuntu and its derivatives: - Ubuntu 16.04 LTS Summary: Drupal could be made to crash or run programs if it received specially crafted network traffic. Software Description: - drupal7: fully-featured content management framework Details: It was discovered that Drupal incorrectly sanitized uploaded filenames. A remote attacker could possibly use this issue to execute arbitrary code. (CVE-2020-13671) It was discovered that Drupal incorrectly sanitized archived filenames. A remote attacker could possibly use this issue to overwrite arbitrary files, or execute arbitrary code. (CVE-2020-28948, CVE-2020-28949) Update instructions: The problem can be corrected by updating your system to the following package versions: Ubuntu 16.04 LTS drupal7 7.44-1ubuntu1~16.04.0+esm2 Available with Ubuntu Pro In general, a standard system update will make all the necessary changes. References: https://ubuntu.com/security/notices/USN-6981-1 CVE-2020-13671, CVE-2020-28948, CVE-2020-28949 . Security flaws in Drupal could allow remote adversaries to compromise the system, potentially leading to crashes or unauthorized program execution through specially designed network packets.. Drupal Security, Remote Code Execution, Ubuntu Advisory. . Severity: Critical. LinuxSecurity.com Team
- [7.98](https://) - [7.97](https://) - [7.96](https://) - [SA- CORE-2023-005](https://) - [7.95](https://) - [SA-. -------------------------------------------------------------------------------- Fedora Update Notification FEDORA-2023-b659c62db9 2023-11-03 18:20:20.950653 -------------------------------------------------------------------------------- Name : drupal7 Product : Fedora 39 Version : 7.98 Release : 1.fc39 URL : https:// Summary : An open-source content-management platform Description : Equipped with a powerful blend of features, Drupal is a Content Management System written in PHP that can support a variety of websites ranging from personal weblogs to large community-driven websites. Drupal is highly configurable, skinnable, and secure. -------------------------------------------------------------------------------- Update Information: - [7.98](https://) - [7.97](https://) - [7.96](https://) - [SA- CORE-2023-005](https://) - [7.95](https://) - [SA- CORE-2023-004](https://) - [7.94](https://) - [7.93](https://) -------------------------------------------------------------------------------- ChangeLog: * Tue Sep 26 2023 Shawn Iwinski - 7.98-1 - Update to 7.98 (RHBZ #2217253) - SA-CORE-2023-004 - SA-CORE-2023-005 (RHBZ #2188106, 2188107, 2188108) -------------------------------------------------------------------------------- References: [ 1 ] Bug #2188107 - drupal7: drupal: File download facility doesn't sufficiently sanitize file paths [fedora-all] https://bugzilla.redhat.com/show_bug.cgi?id=2188107 [ 2 ] Bug #2188108 - drupal7: drupal: File download facility doesn't sufficiently sanitize file paths [epel-7] https://bugzilla.redhat.com/show_bug.cgi?id=2188108 [ 3 ] Bug #2217253 - drupal7-7.98 is available https://bugzilla.redhat.com/show_bug.cgi?id=2217253 -------------------------------------------------------------------------------- This update can be installed withthe "dnf" update program. Use su -c 'dnf upgrade --advisory FEDORA-2023-b659c62db9' at the command line. For more information, refer to the dnf documentation available at https://dnf.readthedocs.io/en/latest/command_ref.html All packages are signed with the Fedora Project GPG key. More details on the GPG keys used by the Fedora Project can be found at https://fedoraproject.org/security/ -------------------------------------------------------------------------------- _______________________________________________ package-announce mailing list --
-------------------------------------------------------------------------------- Fedora Update Notification FEDORA-2009-0653 2009-01-16 22:40:02 -------------------------------------------------------------------------------- Name : drupal Product : Fedora 10 Version : 6.9 Release : 1.fc10 URL : http://www.drupal.org Summary : An open-source content-management platform Description : Equipped with a powerful blend of features, Drupal is a Content Management System written in PHP that can support a variety of websites ranging from personal weblogs to large community-driven websites. Drupal is highly configurable, skinnable, and secure. -------------------------------------------------------------------------------- Update Information: SA-CORE-2009-001 ( https:// ) Remember to log in to your site as the admin user before upgrading this package. After upgrading the package, browse to to run the upgrade script. -------------------------------------------------------------------------------- ChangeLog: * Thu Jan 15 2009 Jon Ciesla - 6.9-1 - Upgrade to 6.9, DRUPAL-SA-CORE-2009-001. * Thu Dec 11 2008 Jon Ciesla - 6.7-1 - Upgrade to 6.7, SA-2008-073. -------------------------------------------------------------------------------- This update can be installed with the "yum" update program. Use su -c 'yum update drupal' at the command line. For more information, refer to "Managing Software with yum", available at . All packages are signed with the Fedora Project GPG key. More details on the GPG keys used by the Fedora Project can be found at https://fedoraproject.org/security/ -------------------------------------------------------------------------------- _______________________________________________ Fedora-package-announce mailing list
- - - - - - [SA-. --------------------------------------------------------------------------------Fedora Update Notification FEDORA-2022-8b770865e3 2022-11-27 01:29:58.629576 --------------------------------------------------------------------------------Name : drupal7-i18n Product : Fedora 37 Version : 1.31 Release : 1.fc37 URL : Summary : Enables multilingual content Description : This is a collection of modules to extend Drupal core multilingual capabilities and be able to build real life multilingual sites. Some features: * Taxonomy translation (both, per language terms and translatable terms) * Multilingual variables * Multilingual blocks (control visibility per language and translate title and content) * Language selection (when you switch the site language you'll see only the content for that language) Read a complete feature overview in the Internationalization handbook: Building multilingual sites [1]. This package provides the following Drupal modules: * i18n * i18n_block * i18n_contact * i18n_field * i18n_forum * i18n_menu * i18n_node * i18n_path * i18n_redirect * i18n_select * i18n_string * i18n_sync * i18n_taxonomy * i18n_translation * i18n_user * i18n_variable [1] --------------------------------------------------------------------------------Update Information: - - - - - - [SA-CONTRIB-2020-025]() --------------------------------------------------------------------------------ChangeLog: * Thu Nov 17 2022 Shawn Iwinski - 1.31-1 - Update to 1.31 (RHBZ #1848185) --------------------------------------------------------------------------------References: [ 1 ] Bug #1848185 - drupal7-i18n-1.31 is available https://bugzilla.redhat.com/show_bug.cgi?id=1848185 --------------------------------------------------------------------------------This update can be installed with the "dnf" update program. Use su -c 'dnf upgrade --advisory FEDORA-2022-8b770865e3' at the command line. Formore information, refer to the dnf documentation available at https://dnf.readthedocs.io/en/latest/command_ref.html All packages are signed with the Fedora Project GPG key. More details on the GPG keys used by the Fedora Project can be found at https://fedoraproject.org/security/ --------------------------------------------------------------------------------_______________________________________________ package-announce mailing list --
- [7.92]() - [7.91]() - [SA-CORE-2022-012 / CVE-2022-25275]() - [7.90]() - [7.89]() -. --------------------------------------------------------------------------------Fedora Update Notification FEDORA-2022-c4334d5277 2022-11-10 22:04:44.630660 --------------------------------------------------------------------------------Name : drupal7 Product : Fedora 37 Version : 7.92 Release : 1.fc37 URL : Summary : An open-source content-management platform Description : Equipped with a powerful blend of features, Drupal is a Content Management System written in PHP that can support a variety of websites ranging from personal weblogs to large community-driven websites. Drupal is highly configurable, skinnable, and secure. --------------------------------------------------------------------------------Update Information: - [7.92]() -[7.91]() - [SA-CORE-2022-012 / CVE-2022-25275]() -[7.90]() -[7.89]() -[7.88]() - [SA-CORE-2022-003 / CVE-2022-25271]() -[7.87]() -[7.86]() - [SA-CORE-2022-001 / CVE-2021-41184]() -[SA-CORE-2022-002 / CVE-2021-41182 / CVE-2021-41183 / CVE-2016-7103 / CVE-2010-5312]() -[7.85]() -[7.84]() -[7.83]() --------------------------------------------------------------------------------ChangeLog: * Sat Oct 15 2022 Shawn Iwinski - 7.92-1 - Update to 7.92 - SA-CORE-2022-012 / CVE-2022-25275 - SA-CORE-2022-003 / CVE-2022-25271 (RHBZ #2055472, 2055473) - SA-CORE-2022-001 / CVE-2021-41184 - SA-CORE-2022-002 / CVE-2021-41182 / CVE-2021-41183 --------------------------------------------------------------------------------References: [ 1 ] Bug #2055472 - CVE-2022-25271 drupal7: drupal: improper input validation found via drupal core api [epel-all] https://bugzilla.redhat.com/show_bug.cgi?id=2055472 [ 2 ] Bug #2055473 - CVE-2022-25271 drupal7: drupal: improper input validation found via drupal core api [fedora-all] https://bugzilla.redhat.com/show_bug.cgi?id=2055473 --------------------------------------------------------------------------------This update can be installed with the "dnf" update program. Use su -c 'dnf upgrade --advisory FEDORA-2022-c4334d5277' at the command line. For more information, refer to the dnf documentation available at https://dnf.readthedocs.io/en/latest/command_ref.html All packages are signed with the Fedora Project GPG key. More details on the GPG keys used by the Fedora Project can be found at https://fedoraproject.org/security/ --------------------------------------------------------------------------------_______________________________________________ package-announce mailing list --
- [7.92]() - [7.91]() - [SA-CORE-2022-012 / CVE-2022-25275]() - [7.90]() - [7.89]() -. --------------------------------------------------------------------------------Fedora Update Notification FEDORA-2022-9d655503ea 2022-10-23 09:02:48.673645 --------------------------------------------------------------------------------Name : drupal7 Product : Fedora 36 Version : 7.92 Release : 1.fc36 URL : Summary : An open-source content-management platform Description : Equipped with a powerful blend of features, Drupal is a Content Management System written in PHP that can support a variety of websites ranging from personal weblogs to large community-driven websites. Drupal is highly configurable, skinnable, and secure. --------------------------------------------------------------------------------Update Information: - [7.92]() -[7.91]() - [SA-CORE-2022-012 / CVE-2022-25275]() -[7.90]() -[7.89]() -[7.88]() - [SA-CORE-2022-003 / CVE-2022-25271]() -[7.87]() -[7.86]() - [SA-CORE-2022-001 / CVE-2021-41184]() -[SA-CORE-2022-002 / CVE-2021-41182 / CVE-2021-41183 / CVE-2016-7103 / CVE-2010-5312]() -[7.85]() -[7.84]() -[7.83]() --------------------------------------------------------------------------------ChangeLog: * Sat Oct 15 2022 Shawn Iwinski - 7.92-1 - Update to 7.92 - SA-CORE-2022-012 / CVE-2022-25275 - SA-CORE-2022-003 / CVE-2022-25271 (RHBZ #2055472, 2055473) - SA-CORE-2022-001 / CVE-2021-41184 - SA-CORE-2022-002 / CVE-2021-41182 / CVE-2021-41183 * Thu Jul 21 2022 Fedora Release Engineering - 7.82-3 - Rebuilt for https://fedoraproject.org/wiki/Fedora_37_Mass_Rebuild --------------------------------------------------------------------------------References: [ 1 ] Bug #2055472 - CVE-2022-25271 drupal7: drupal: improper input validation found via drupal core api [epel-all] https://bugzilla.redhat.com/show_bug.cgi?id=2055472 [ 2 ] Bug #2055473 - CVE-2022-25271 drupal7: drupal: improper input validation found via drupalcore api [fedora-all] https://bugzilla.redhat.com/show_bug.cgi?id=2055473 --------------------------------------------------------------------------------This update can be installed with the "dnf" update program. Use su -c 'dnf upgrade --advisory FEDORA-2022-9d655503ea' at the command line. For more information, refer to the dnf documentation available at https://dnf.readthedocs.io/en/latest/command_ref.html All packages are signed with the Fedora Project GPG key. More details on the GPG keys used by the Fedora Project can be found at https://fedoraproject.org/security/ --------------------------------------------------------------------------------_______________________________________________ package-announce mailing list --
This security updates includes two fixes, backported respectively from Drupal version 7.87 and 7.88: - Fix a regression caused by Query ui position() backport in version . Package : drupal7 Version : 7.52-2+deb9u18 This security updates includes two fixes, backported respectively from Drupal version 7.87 and 7.88: - Fix a regression caused by Query ui position() backport in version 7.86 (backported as 7.52-2+deb9u17): was not checking for possible "undefined" value in options - Fix improper input validation in Drupal's form API Drupal is a dynamic web site platform which allows an individual or community of users to publish, manage and organize a variety of content. . WordPress 5.8.1-1+deb10u12 patch resolves bugs and improves interface reliability, boosting security measures and performance.. Drupal Security Update, Drupal Input Validation, Drupal Patch. . LinuxSecurity.com Team
Get the latest Linux and open source security news straight to your inbox.