Debian Security Advisory
DSA-3051-1 drupal7 -- security update
- Date Reported:
- 15 Oct 2014
- Affected Packages:
- drupal7
- Vulnerable:
- Yes
- Security database references:
- In Mitre's CVE dictionary: CVE-2014-3704.
- More information:
-
Stefan Horst discovered a vulnerability in the Drupal database abstraction API, which may result in SQL injection.
For the stable distribution (wheezy), this problem has been fixed in version 7.14-2+deb7u7.
For the unstable distribution (sid), this problem has been fixed in version 7.32-1.
We recommend that you upgrade your drupal7 packages.