Audit Linux privileges now to limit compromise, escalation, and system-wide damage. Review Linux Privileges×
https:// https:// https:// https:// https://. -------------------------------------------------------------------------------- Fedora Update Notification FEDORA-2025-f8a08bb335 2025-11-29 17:02:16.261291+00:00 -------------------------------------------------------------------------------- Name : drupal7 Product : Fedora 42 Version : 7.103 Release : 1.fc42 URL : https:// Summary : An open-source content-management platform Description : Equipped with a powerful blend of features, Drupal is a Content Management System written in PHP that can support a variety of websites ranging from personal weblogs to large community-driven websites. Drupal is highly configurable, skinnable, and secure. -------------------------------------------------------------------------------- Update Information: https:// https:// https:// https:// https:// https:// https:// -------------------------------------------------------------------------------- ChangeLog: * Wed Nov 19 2025 Shawn Iwinski - 7.103-1 - Update to 7.103 (RHBZ #2253220) - SA-CORE-2024-005 / CVE-2024-55635 - SA-CORE-2024-008 / CVE-2024-55638 * Wed Jul 23 2025 Fedora Release Engineering - 7.98-7 - Rebuilt for https://fedoraproject.org/wiki/Fedora_43_Mass_Rebuild -------------------------------------------------------------------------------- References: [ 1 ] Bug #2253220 - drupal7-7.103 is available https://bugzilla.redhat.com/show_bug.cgi?id=2253220 -------------------------------------------------------------------------------- This update can be installed with the "dnf" update program. Use su -c 'dnf upgrade --advisory FEDORA-2025-f8a08bb335' at the command line. For more information, refer to the dnf documentation available at http://dnf.readthedocs.io/en/latest/command_ref.html#upgrade-command-label All packages are signed with the Fedora Project GPG key. More details on the GPG keys used by the Fedora Project can be foundat https://fedoraproject.org/keys -------------------------------------------------------------------------------- -- _______________________________________________ package-announce mailing list --
https:// https:// https:// https:// https://. -------------------------------------------------------------------------------- Fedora Update Notification FEDORA-2025-355d5aac01 2025-11-29 16:43:28.332599+00:00 -------------------------------------------------------------------------------- Name : drupal7 Product : Fedora 43 Version : 7.103 Release : 1.fc43 URL : https:// Summary : An open-source content-management platform Description : Equipped with a powerful blend of features, Drupal is a Content Management System written in PHP that can support a variety of websites ranging from personal weblogs to large community-driven websites. Drupal is highly configurable, skinnable, and secure. -------------------------------------------------------------------------------- Update Information: https:// https:// https:// https:// https:// https:// https:// -------------------------------------------------------------------------------- ChangeLog: * Wed Nov 19 2025 Shawn Iwinski - 7.103-1 - Update to 7.103 (RHBZ #2253220) - SA-CORE-2024-005 / CVE-2024-55635 - SA-CORE-2024-008 / CVE-2024-55638 -------------------------------------------------------------------------------- References: [ 1 ] Bug #2253220 - drupal7-7.103 is available https://bugzilla.redhat.com/show_bug.cgi?id=2253220 -------------------------------------------------------------------------------- This update can be installed with the "dnf" update program. Use su -c 'dnf upgrade --advisory FEDORA-2025-355d5aac01' at the command line. For more information, refer to the dnf documentation available at http://dnf.readthedocs.io/en/latest/command_ref.html#upgrade-command-label All packages are signed with the Fedora Project GPG key. More details on the GPG keys used by the Fedora Project can be found at https://fedoraproject.org/keys -------------------------------------------------------------------------------- -- _______________________________________________ package-announce mailing list --
https:// https:// https:// https:// https://. -------------------------------------------------------------------------------- Fedora Update Notification FEDORA-2025-d645721ca4 2025-11-29 16:05:06.047940+00:00 -------------------------------------------------------------------------------- Name : drupal7 Product : Fedora 41 Version : 7.103 Release : 1.fc41 URL : https:// Summary : An open-source content-management platform Description : Equipped with a powerful blend of features, Drupal is a Content Management System written in PHP that can support a variety of websites ranging from personal weblogs to large community-driven websites. Drupal is highly configurable, skinnable, and secure. -------------------------------------------------------------------------------- Update Information: https:// https:// https:// https:// https:// https:// https:// -------------------------------------------------------------------------------- ChangeLog: * Wed Nov 19 2025 Shawn Iwinski - 7.103-1 - Update to 7.103 (RHBZ #2253220) - SA-CORE-2024-005 / CVE-2024-55635 - SA-CORE-2024-008 / CVE-2024-55638 * Wed Jul 23 2025 Fedora Release Engineering - 7.98-7 - Rebuilt for https://fedoraproject.org/wiki/Fedora_43_Mass_Rebuild * Thu Jan 16 2025 Fedora Release Engineering - 7.98-6 - Rebuilt for https://fedoraproject.org/wiki/Fedora_42_Mass_Rebuild * Wed Aug 28 2024 Miroslav Such - 7.98-5 - convert license to SPDX -------------------------------------------------------------------------------- References: [ 1 ] Bug #2253220 - drupal7-7.103 is available https://bugzilla.redhat.com/show_bug.cgi?id=2253220 -------------------------------------------------------------------------------- This update can be installed with the "dnf" update program. Use su -c 'dnf upgrade --advisory FEDORA-2025-d645721ca4' at the command line. For more information, refer to the dnf documentation available at http://dnf.readthedocs.io/en/latest/command_ref.html#upgrade-command-label All packages aresigned with the Fedora Project GPG key. More details on the GPG keys used by the Fedora Project can be found at https://fedoraproject.org/keys -------------------------------------------------------------------------------- . Critical Fedora update released for drupal7 addressing core vulnerabilities with strong recommendations for installation.. Fedora security advisory, drupal7 update, software vulnerabilities. . Severity: Critical. LinuxSecurity.com Team
Drupal could be made to crash or run programs if it received specially crafted network traffic.. ========================================================================== Ubuntu Security Notice USN-6981-2 September 03, 2024 drupal7 vulnerabilities ========================================================================== A security issue affects these releases of Ubuntu and its derivatives: - Ubuntu 14.04 LTS Summary: Drupal could be made to crash or run programs if it received specially crafted network traffic. Software Description: - drupal7: fully-featured content management framework Details: USN-6981-1 fixed vulnerabilities in Drupal. This update provides the corresponding updates for Ubuntu 14.04 LTS. Original advisory details: It was discovered that Drupal incorrectly sanitized uploaded filenames. A remote attacker could possibly use this issue to execute arbitrary code. (CVE-2020-13671) It was discovered that Drupal incorrectly sanitized archived filenames. A remote attacker could possibly use this issue to overwrite arbitrary files, or execute arbitrary code. (CVE-2020-28948, CVE-2020-28949) Update instructions: The problem can be corrected by updating your system to the following package versions: Ubuntu 14.04 LTS drupal7 7.26-1ubuntu0.1+esm2 Available with Ubuntu Pro In general, a standard system update will make all the necessary changes. References: https://ubuntu.com/security/notices/USN-6981-2 https://ubuntu.com/security/notices/USN-6981-1 CVE-2020-13671, CVE-2020-28948, CVE-2020-28949 . Alert Announcement USN-6982-1 addresses critical security weaknesses in Drupal 7 for Ubuntu 14.04 LTS, implementing essential updates to safeguard network transmission issues.. Drupal Security, Remote Code Execution, Update Instructions. . Severity: Critical. LinuxSecurity.com Team
- [7.98]() - [7.97]() - [7.96]() - [SA- CORE-2023-005]() - [7.95]() - [SA-. -------------------------------------------------------------------------------- Fedora Update Notification FEDORA-2023-f4d22f8a92 2023-10-04 15:50:14.488586 -------------------------------------------------------------------------------- Name : drupal7 Product : Fedora 38 Version : 7.98 Release : 1.fc38 URL : Summary : An open-source content-management platform Description : Equipped with a powerful blend of features, Drupal is a Content Management System written in PHP that can support a variety of websites ranging from personal weblogs to large community-driven websites. Drupal is highly configurable, skinnable, and secure. -------------------------------------------------------------------------------- Update Information: - [7.98]() - [7.97]() - [7.96]() - [SA- CORE-2023-005]() - [7.95]() - [SA- CORE-2023-004]() - [7.94]() - [7.93]() -------------------------------------------------------------------------------- ChangeLog: * Tue Sep 26 2023 Shawn Iwinski - 7.98-1 - Update to 7.98 (RHBZ #2217253) - SA-CORE-2023-004 - SA-CORE-2023-005 (RHBZ #2188106, 2188107, 2188108) * Wed Jul 19 2023 Fedora Release Engineering - 7.92-3 - Rebuilt for https://fedoraproject.org/wiki/Fedora_39_Mass_Rebuild -------------------------------------------------------------------------------- References: [ 1 ] Bug #2188107 - drupal7: drupal: File download facility doesn't sufficiently sanitize file paths [fedora-all] https://bugzilla.redhat.com/show_bug.cgi?id=2188107 [ 2 ] Bug #2188108 - drupal7: drupal: File download facility doesn't sufficiently sanitize file paths [epel-7] https://bugzilla.redhat.com/show_bug.cgi?id=2188108 [ 3 ] Bug #2217253 - drupal7-7.98 is available https://bugzilla.redhat.com/show_bug.cgi?id=2217253 -------------------------------------------------------------------------------- This update can beinstalled with the "dnf" update program. Use su -c 'dnf upgrade --advisory FEDORA-2023-f4d22f8a92' at the command line. For more information, refer to the dnf documentation available at https://dnf.readthedocs.io/en/latest/command_ref.html All packages are signed with the Fedora Project GPG key. More details on the GPG keys used by the Fedora Project can be found at https://fedoraproject.org/security/ -------------------------------------------------------------------------------- _______________________________________________ package-announce mailing list --
- [7.98]() - [7.97]() - [7.96]() - [SA- CORE-2023-005]() - [7.95]() - [SA-. -------------------------------------------------------------------------------- Fedora Update Notification FEDORA-2023-83aeb73043 2023-10-04 15:47:53.759443 -------------------------------------------------------------------------------- Name : drupal7 Product : Fedora 37 Version : 7.98 Release : 1.fc37 URL : Summary : An open-source content-management platform Description : Equipped with a powerful blend of features, Drupal is a Content Management System written in PHP that can support a variety of websites ranging from personal weblogs to large community-driven websites. Drupal is highly configurable, skinnable, and secure. -------------------------------------------------------------------------------- Update Information: - [7.98]() - [7.97]() - [7.96]() - [SA- CORE-2023-005]() - [7.95]() - [SA- CORE-2023-004]() - [7.94]() - [7.93]() -------------------------------------------------------------------------------- ChangeLog: * Tue Sep 26 2023 Shawn Iwinski - 7.98-1 - Update to 7.98 (RHBZ #2217253) - SA-CORE-2023-004 - SA-CORE-2023-005 (RHBZ #2188106, 2188107, 2188108) * Wed Jul 19 2023 Fedora Release Engineering - 7.92-3 - Rebuilt for https://fedoraproject.org/wiki/Fedora_39_Mass_Rebuild * Thu Jan 19 2023 Fedora Release Engineering - 7.92-2 - Rebuilt for https://fedoraproject.org/wiki/Fedora_38_Mass_Rebuild -------------------------------------------------------------------------------- References: [ 1 ] Bug #2188107 - drupal7: drupal: File download facility doesn't sufficiently sanitize file paths [fedora-all] https://bugzilla.redhat.com/show_bug.cgi?id=2188107 [ 2 ] Bug #2188108 - drupal7: drupal: File download facility doesn't sufficiently sanitize file paths [epel-7] https://bugzilla.redhat.com/show_bug.cgi?id=2188108 [ 3 ] Bug #2217253 - drupal7-7.98 is available https://bugzilla.redhat.com/show_bug.cgi?id=2217253 -------------------------------------------------------------------------------- This update can be installed with the "dnf" update program. Use su -c 'dnf upgrade --advisory FEDORA-2023-83aeb73043' at the command line. For more information, refer to the dnf documentation available at https://dnf.readthedocs.io/en/latest/command_ref.html All packages are signed with the Fedora Project GPG key. More details on the GPG keys used by the Fedora Project can be found at https://fedoraproject.org/security/ -------------------------------------------------------------------------------- _______________________________________________ package-announce mailing list --
- [7.92]() - [7.91]() - [SA-CORE-2022-012 / CVE-2022-25275]() - [7.90]() - [7.89]() -. --------------------------------------------------------------------------------Fedora Update Notification FEDORA-2022-bf18450366 2022-11-03 15:30:27.308055 --------------------------------------------------------------------------------Name : drupal7 Product : Fedora 35 Version : 7.92 Release : 1.fc35 URL : Summary : An open-source content-management platform Description : Equipped with a powerful blend of features, Drupal is a Content Management System written in PHP that can support a variety of websites ranging from personal weblogs to large community-driven websites. Drupal is highly configurable, skinnable, and secure. --------------------------------------------------------------------------------Update Information: - [7.92]() -[7.91]() - [SA-CORE-2022-012 / CVE-2022-25275]() -[7.90]() -[7.89]() -[7.88]() - [SA-CORE-2022-003 / CVE-2022-25271]() -[7.87]() -[7.86]() - [SA-CORE-2022-001 / CVE-2021-41184]() -[SA-CORE-2022-002 / CVE-2021-41182 / CVE-2021-41183 / CVE-2016-7103 / CVE-2010-5312]() -[7.85]() -[7.84]() -[7.83]() --------------------------------------------------------------------------------ChangeLog: * Sat Oct 15 2022 Shawn Iwinski - 7.92-1 - Update to 7.92 - SA-CORE-2022-012 / CVE-2022-25275 - SA-CORE-2022-003 / CVE-2022-25271 (RHBZ #2055472, 2055473) - SA-CORE-2022-001 / CVE-2021-41184 - SA-CORE-2022-002 / CVE-2021-41182 / CVE-2021-41183 * Thu Jul 21 2022 Fedora Release Engineering - 7.82-3 - Rebuilt for https://fedoraproject.org/wiki/Fedora_37_Mass_Rebuild * Thu Jan 20 2022 Fedora Release Engineering - 7.82-2 - Rebuilt for https://fedoraproject.org/wiki/Fedora_36_Mass_Rebuild --------------------------------------------------------------------------------References: [ 1 ] Bug #2055473 - CVE-2022-25271 drupal7: drupal: improper input validation found via drupal core api [fedora-all] https://bugzilla.redhat.com/show_bug.cgi?id=2055473 --------------------------------------------------------------------------------This update can be installed with the "dnf" update program. Use su -c 'dnf upgrade --advisory FEDORA-2022-bf18450366' at the command line. For more information, refer to the dnf documentation available at https://dnf.readthedocs.io/en/latest/command_ref.html All packages are signed with the Fedora Project GPG key. More details on the GPG keys used by the Fedora Project can be found at https://fedoraproject.org/security/ --------------------------------------------------------------------------------_______________________________________________ package-announce mailing list --
The Drupal project uses the pear Archive_Tar library, which has released a security update that impacts Drupal. The vulnerability is mitigated by the fact that Drupal core's use of . ------------------------------------------------------------------------- Debian LTS Advisory DLA-2721-1
Get the latest Linux and open source security news straight to your inbox.