You are here
Home > Preporuke > Sigurnosni nedostaci programskog paketa drupal7

Sigurnosni nedostaci programskog paketa drupal7

  • Detalji os-a: WN7
  • Važnost: IMP
  • Operativni sustavi: L
  • Kategorije: LFE

——————————————————————————–
Fedora Update Notification
FEDORA-2018-d8269e4262
2018-04-10 18:29:01.403117
——————————————————————————–

Name : drupal7
Product : Fedora 26
Version : 7.58
Release : 1.fc26
URL : http://www.drupal.org
Summary : An open-source content-management platform
Description :
Equipped with a powerful blend of features, Drupal is a Content Management
System written in PHP that can support a variety of websites ranging from
personal weblogs to large community-driven websites. Drupal is highly
configurable, skinnable, and secure.

——————————————————————————–
Update Information:

– https://www.drupal.org/SA-CORE-2018-002 – https://www.drupal.org/SA-
CORE-2018-001
——————————————————————————–
References:

[ 1 ] Bug #1548190 – drupal7: drupal: JavaScript cross-site scripting in checkPlain function [fedora-all]
https://bugzilla.redhat.com/show_bug.cgi?id=1548190
[ 2 ] Bug #1547793 – drupal7-7.57 is available
https://bugzilla.redhat.com/show_bug.cgi?id=1547793
[ 3 ] Bug #1548324 – CVE-2017-6926 CVE-2017-6927 CVE-2017-6928 CVE-2017-6929 CVE-2017-6930 CVE-2017-6931 CVE-2017-6932 drupal7: drupal: Multiple vulnerabilities fixed in 7.57 and 8.4.5 (SA-CORE-2018-001) [epel-all]
https://bugzilla.redhat.com/show_bug.cgi?id=1548324
[ 4 ] Bug #1548201 – drupal7: drupal: External link injection on 404 pages when linking to the current page [epel-all]
https://bugzilla.redhat.com/show_bug.cgi?id=1548201
[ 5 ] Bug #1548197 – drupal7: drupal: jQuery vulnerability with untrusted domains requests via Ajax [epel-all]
https://bugzilla.redhat.com/show_bug.cgi?id=1548197
[ 6 ] Bug #1548195 – drupal7: drupal: Private file access bypass in Drupal private file system [epel-all]
https://bugzilla.redhat.com/show_bug.cgi?id=1548195
[ 7 ] Bug #1561801 – drupal7-7.58 is available
https://bugzilla.redhat.com/show_bug.cgi?id=1561801
[ 8 ] Bug #1548191 – drupal7: drupal: JavaScript cross-site scripting in checkPlain function [epel-all]
https://bugzilla.redhat.com/show_bug.cgi?id=1548191
[ 9 ] Bug #1548326 – CVE-2017-6926 CVE-2017-6927 CVE-2017-6928 CVE-2017-6929 CVE-2017-6930 CVE-2017-6931 CVE-2017-6932 drupal7: drupal: Multiple vulnerabilities fixed in 7.57 and 8.4.5 (SA-CORE-2018-001) [fedora-all]
https://bugzilla.redhat.com/show_bug.cgi?id=1548326
[ 10 ] Bug #1548202 – drupal7: drupal: External link injection on 404 pages when linking to the current page [fedora-all]
https://bugzilla.redhat.com/show_bug.cgi?id=1548202
[ 11 ] Bug #1548198 – drupal7: drupal: jQuery vulnerability with untrusted domains requests via Ajax [fedora-all]
https://bugzilla.redhat.com/show_bug.cgi?id=1548198
[ 12 ] Bug #1548194 – drupal7: drupal: Private file access bypass in Drupal private file system [fedora-all]
https://bugzilla.redhat.com/show_bug.cgi?id=1548194
——————————————————————————–

This update can be installed with the “dnf” update program. Use
su -c ‘dnf upgrade drupal7’ at the command line.
For more information, refer to the dnf documentation available at
http://dnf.readthedocs.io/en/latest/command_ref.html#upgrade-command-label

All packages are signed with the Fedora Project GPG key. More details on the
GPG keys used by the Fedora Project can be found at
https://fedoraproject.org/keys
——————————————————————————–
_______________________________________________
package-announce mailing list — package-announce@lists.fedoraproject.org
To unsubscribe send an email to package-announce-leave@lists.fedoraproject.org

——————————————————————————–
Fedora Update Notification
FEDORA-2018-143886fdbd
2018-04-10 19:09:15.785773
——————————————————————————–

Name : drupal7
Product : Fedora 27
Version : 7.58
Release : 1.fc27
URL : http://www.drupal.org
Summary : An open-source content-management platform
Description :
Equipped with a powerful blend of features, Drupal is a Content Management
System written in PHP that can support a variety of websites ranging from
personal weblogs to large community-driven websites. Drupal is highly
configurable, skinnable, and secure.

——————————————————————————–
Update Information:

– https://www.drupal.org/SA-CORE-2018-002 – https://www.drupal.org/SA-
CORE-2018-001
——————————————————————————–
References:

[ 1 ] Bug #1548190 – drupal7: drupal: JavaScript cross-site scripting in checkPlain function [fedora-all]
https://bugzilla.redhat.com/show_bug.cgi?id=1548190
[ 2 ] Bug #1547793 – drupal7-7.57 is available
https://bugzilla.redhat.com/show_bug.cgi?id=1547793
[ 3 ] Bug #1548324 – CVE-2017-6926 CVE-2017-6927 CVE-2017-6928 CVE-2017-6929 CVE-2017-6930 CVE-2017-6931 CVE-2017-6932 drupal7: drupal: Multiple vulnerabilities fixed in 7.57 and 8.4.5 (SA-CORE-2018-001) [epel-all]
https://bugzilla.redhat.com/show_bug.cgi?id=1548324
[ 4 ] Bug #1548201 – drupal7: drupal: External link injection on 404 pages when linking to the current page [epel-all]
https://bugzilla.redhat.com/show_bug.cgi?id=1548201
[ 5 ] Bug #1548197 – drupal7: drupal: jQuery vulnerability with untrusted domains requests via Ajax [epel-all]
https://bugzilla.redhat.com/show_bug.cgi?id=1548197
[ 6 ] Bug #1548195 – drupal7: drupal: Private file access bypass in Drupal private file system [epel-all]
https://bugzilla.redhat.com/show_bug.cgi?id=1548195
[ 7 ] Bug #1561801 – drupal7-7.58 is available
https://bugzilla.redhat.com/show_bug.cgi?id=1561801
[ 8 ] Bug #1548191 – drupal7: drupal: JavaScript cross-site scripting in checkPlain function [epel-all]
https://bugzilla.redhat.com/show_bug.cgi?id=1548191
[ 9 ] Bug #1548326 – CVE-2017-6926 CVE-2017-6927 CVE-2017-6928 CVE-2017-6929 CVE-2017-6930 CVE-2017-6931 CVE-2017-6932 drupal7: drupal: Multiple vulnerabilities fixed in 7.57 and 8.4.5 (SA-CORE-2018-001) [fedora-all]
https://bugzilla.redhat.com/show_bug.cgi?id=1548326
[ 10 ] Bug #1548202 – drupal7: drupal: External link injection on 404 pages when linking to the current page [fedora-all]
https://bugzilla.redhat.com/show_bug.cgi?id=1548202
[ 11 ] Bug #1548198 – drupal7: drupal: jQuery vulnerability with untrusted domains requests via Ajax [fedora-all]
https://bugzilla.redhat.com/show_bug.cgi?id=1548198
[ 12 ] Bug #1548194 – drupal7: drupal: Private file access bypass in Drupal private file system [fedora-all]
https://bugzilla.redhat.com/show_bug.cgi?id=1548194
——————————————————————————–

This update can be installed with the “dnf” update program. Use
su -c ‘dnf upgrade drupal7’ at the command line.
For more information, refer to the dnf documentation available at
http://dnf.readthedocs.io/en/latest/command_ref.html#upgrade-command-label

All packages are signed with the Fedora Project GPG key. More details on the
GPG keys used by the Fedora Project can be found at
https://fedoraproject.org/keys
——————————————————————————–
_______________________________________________
package-announce mailing list — package-announce@lists.fedoraproject.org
To unsubscribe send an email to package-announce-leave@lists.fedoraproject.org

AutorPetar Bertok
Cert idNCERT-REF-2018-04-0001-ADV
CveCERT-CVE-DUMMY
ID izvornikaCERT-ORIGID-DUMMY
ProizvodCERT-DUMMY-PRODUCT
IzvorAdobe
Top
More in Preporuke
Sigurnosni nedostaci programskog paketa firefox

Otkriveni su sigurnosni nedostaci u programskom paketu firefox za operacijski sustav Red Hat. Otkriveni nedostaci potencijalnim napadačima omogućuju izvršavanje proizvoljnog...

Close