Download Drupal 7.62 / 8.5.9 / 8.6.6
Updates have been released for versions 7, 8.5 and 8.6 from Drupal, which should fix various vulnerabilities. Drupal is a PHP-written, user-friendly and powerful content management platform, with which, for example, websites can be created. It’s simple enough for a novice user, but powerful enough to build a more complex website as well. The program includes a content management platform and a development framework. Advisory SA-CORE-2019-001 reports fixing a vulnerability in the PEAR Archive_Tar library.
security risk:
Critical 16∕25 AC:Complex/A:User/CI:All/II:All/E:Proof/TD:Uncommon
Vulnerability:
Third Party Libraries
Description:
Drupal core uses the third-party PEAR Archive_Tar library. This library has released a security update which impacts some Drupal configurations. refer to CVE-2018-1000888 for details.
Solution:
- If you are using Drupal 8.6.x, upgrade to Drupal 8.6.6.
- If you are using Drupal 8.5.x or earlier, upgrade to Drupal 8.5.9.
- If you are using Drupal 7.x, upgrade to Drupal 7.62.
Versions of Drupal 8 prior to 8.5.x are end-of-life and do not receive security coverage.
Version number | 7.62 / 8.5.9 / 8.6.6 |
Release status | Final |
Operating systems | script language |
Website | Drupal |
Download | |
License type | GPL |