Debian Security Advisory

DLA-1550-1 drupal7 -- LTS security update

Date Reported:
19 Oct 2018
Affected Packages:
drupal7
Vulnerable:
Yes
Security database references:
No other external database security references currently available.
More information:

It was discovered that there was a remote code execution and an external URL injection vulnerability in the Drupal content management framework.

For more information, please see:

https://www.drupal.org/sa-core-2018-006

For Debian 8 Jessie, these issues have been fixed in drupal7 version 7.32-1+deb8u13.

We recommend that you upgrade your drupal7 packages.