Zum Inhalt springen.
Sympa Menü

it-securitynotifies - [IT-SecNots] [SECURITY] [DSA 4693-1] drupal7 security update

it-securitynotifies AT lists.piratenpartei.de

Betreff: Sicherheitsankündigungen

Listenarchiv

[IT-SecNots] [SECURITY] [DSA 4693-1] drupal7 security update


Chronologisch Thread 
  • From: Moritz Muehlenhoff <jmm AT debian.org>
  • To: debian-security-announce AT lists.debian.org
  • Subject: [IT-SecNots] [SECURITY] [DSA 4693-1] drupal7 security update
  • Date: Tue, 26 May 2020 21:08:21 +0000
  • List-archive: https://lists.debian.org/msgid-search/20200526210821.GA1285 AT seger.debian.org
  • List-id: <debian-security-announce.lists.debian.org>
  • List-url: <http://lists.debian.org/debian-security-announce/>
  • Old-dkim-signature: v=1; a=rsa-sha256; q=dns/txt; c=relaxed/relaxed; d=debian.org; s=smtpauto.seger; h=Content-Type:MIME-Version:Message-ID:Subject:To:From: Date:Reply-To:Cc:Content-Transfer-Encoding:Content-ID:Content-Description: In-Reply-To:References; bh=anT6isEBDZOdPtU10/0p6qel1RV2ScsyUHOkudMqEW4=; b=Y0 UZmTorg8nI2RTDvT4wqY7cwjDR7J574mNDy9F/IxA8KjdaBwROZizCO+BI6Igaj9ydtVkLPet0ylF gLRZqpYwCwhuRPtoq49NLfHbAlSXsEIOVx6tNHX7bTAmiWgQh7EbpBpzpijU/ekw8KtwVTDeGqIcp UuhfhpCxjEKnRVArjp37T/QJ9OIwFBI7ZQt8uKY9YbCMQVKUJSkisi+taj0E5twbgUlzBol0zJV2Q fPkGZYkMj+Uheya0psNuAeL9N8ocOVHfTZZqKwnpS6UWgdN7aZ3gQ5nZDWjT/Da4+TkCTxa7z71oD EVLsmQws9MajKYXJvcQlEBX0N9OoZvEA==;
  • Old-return-path: <jmm AT seger.debian.org>
  • Priority: urgent
  • Resent-date: Tue, 26 May 2020 21:08:38 +0000 (UTC)
  • Resent-from: debian-security-announce AT lists.debian.org
  • Resent-message-id: <iRkDyFu-EiD.A.8wD.WVYzeB@bendel>
  • Resent-sender: debian-security-announce-request AT lists.debian.org

-----BEGIN PGP SIGNED MESSAGE-----
Hash: SHA512

- -------------------------------------------------------------------------
Debian Security Advisory DSA-4693-1 security AT debian.org
https://www.debian.org/security/ Moritz Muehlenhoff
May 26, 2020 https://www.debian.org/security/faq
- -------------------------------------------------------------------------

Package : drupal7
CVE ID : CVE-2020-11022 CVE-2020-11023 SA-CORE-2020-003

Several vulnerabilities were discovered in Drupal, a fully-featured
content management framework, which could result in an open redirect or
cross-site scripting.

For the oldstable distribution (stretch), these problems have been fixed
in version 7.52-2+deb9u10.

We recommend that you upgrade your drupal7 packages.

For the detailed security status of drupal7 please refer to
its security tracker page at:
https://security-tracker.debian.org/tracker/drupal7

Further information about Debian Security Advisories, how to apply
these updates to your system and frequently asked questions can be
found at: https://www.debian.org/security/

Mailing list: debian-security-announce AT lists.debian.org
-----BEGIN PGP SIGNATURE-----

iQIzBAEBCgAdFiEEtuYvPRKsOElcDakFEMKTtsN8TjYFAl7NhRgACgkQEMKTtsN8
TjZELQ//ao+AlYru8sTlC4Axs1r3QfXyq/FFn55C2faDkZonWP3+S4O5GjJaDwcH
q9J1OBhvlkTsRkP55qGplUi9pLxs8OTdnJD5VnRXsvijVEhhZ5DOYnLJcLQ5Ggq5
Io8ImGbrGY64qItxmEXUyFfI0YrJ/s1aagUBodORaF6yeJ6DwqIxRVRBS4A3UD61
AH0u/cw69y7WHf1FLpPYAWZSZ0lzkPFxUbi8DlYzwPZApQfhOFCYoWjdziUbxZUU
yZH8M0CORFG2ron8K+sbgKPpepRc6u55OxYU1WxzejJSfKKnGhhaNBrztbgomtIB
pLQ+BSB2tD5iOR/QcdXgmhhTrApUSiR6dF2iPwXt1Bo2+1l2ChEVYfi1q1ggTx5O
e6xulfy+3xSPI4afi4gL1KTHJkg9OZnU1pST3kSxBp/gp+/I473EYqwzhlB14msU
SqNy5kId+GsYzMsvcufbOEsqR2ffAGDz9RNPF7NkfphvAT9YyaXq0kgmnxtMiac1
Um1/7oDh4dZBTzFNnvWRYWQcydgfDvEzW1TQdCd2hp8YTXjhCFNeJrxQx0O9eLxv
jcWC+z0rfQeiUAk7VtqeoCDRS6deVxm1TfXXcV0vgyKGQh5/FBVo9V2L9ag/8phO
0l0TPROG766wZDooBFXNWerf85AT5zCIFopeZopPyuQNIjJA2UU=
=yOQd
-----END PGP SIGNATURE-----



  • [IT-SecNots] [SECURITY] [DSA 4693-1] drupal7 security update, Moritz Muehlenhoff, 26.05.2020

Archiv bereitgestellt durch MHonArc 2.6.19.

Seitenanfang