Drupal Á½¸öËÁÒâ´úÂëÖ´Ðзì϶°²È«¹«¸æ
°ä²¼¹¦·ò 2019-01-18·ì϶±àºÅºÍ¼¶±ð
ÔÝÎÞ ÑϳÁ CVSS·ÖÖµ£º¹Ù·½Î´ÆÀ¶¨
ÔÝÎÞ ÑϳÁ CVSS·ÖÖµ£º¹Ù·½Î´ÆÀ¶¨
Ó°Ïì°æ±¾
Drupal 8.6.x.
Drupal 8.5.x.
Drupal 7.x.
·ì϶¸ÅÊö
1ÔÂ17ÈÕ£¬£¬£¬£¬£¬£¬Drupal°ä²¼ÁËDrupal 7,8.5ºÍ8.6µÄ°²È«¸üУ¬£¬£¬£¬£¬£¬½â¾öÁËÁ½¸ö¿ÉÄܱ»ÀûÓÃÀ´Ö´ÐÐËÁÒâ´úÂëµÄ¡°¹Ø¼ü¡±°²È«·ì϶¡£¡£¡£¡£¡£¡£¡£
Ô¶³Ì¹¥»÷ÕßÄܹ»ÀûÓõÚÒ»¸ö·ì϶À´Ö´ÐÐËÁÒâPHP´úÂë¡£¡£¡£¡£¡£¡£¡£¸Ã·ì϶´æÔÚÓÚPHPÖÐʵÏÖµÄpharÁ÷°ü×°ÖУ¬£¬£¬£¬£¬£¬Óë´¦Öò»ÊÜÐÅÀµµÄphar:// URIµÄ·½Ê½Óйء£¡£¡£¡£¡£¡£¡£
һЩDrupal´úÂë¿ÉÄÜÔÚ¶ÔûÓо¹ý³ä·ÖÑéÖ¤µÄÓû§ÊäÈëÖ´ÐÐÎļþ²Ù×÷£¬£¬£¬£¬£¬£¬´Ó¶øÂ¶³öÓÚ´Ë·ì϶¡£¡£¡£¡£¡£¡£¡£
´úÂëõ辶ͨ³£±ØÒª½Ó¼ûÖÎÀíȨÏÞ»ò·ÇµäÐÍÅäÖ㬣¬£¬£¬£¬£¬´Ó¶ø¼õÇáÁË´Ë·ì϶¡£¡£¡£¡£¡£¡£¡£
µÚ¶þ¸ö·ì϶ӰÏìÁËPEAR Archive_Tar£¬£¬£¬£¬£¬£¬ÕâÊÇÒ»¸öÓÃPHP´¦ÖÃ.tarÎļþµÄµÚÈý·½¿â¡£¡£¡£¡£¡£¡£¡£¹¥»÷ÕßÄܹ»Ê¹ÓÃÌØÔìµÄ.tarÎļþɾ³ýϵͳÉϵÄËÁÒâÎļþ£¬£¬£¬£¬£¬£¬ÉõÖÁ¿ÉÄÜÖ´ÐÐÔ¶³Ì´úÂë¡£¡£¡£¡£¡£¡£¡£¸Ã¿â°ä²¼ÁËÒ»¸ö°²È«¸üУ¬£¬£¬£¬£¬£¬Ëü»áÓ°ÏìһЩDrupalÅäÖᣡ£¡£¡£¡£¡£¡£ÓйؾßÌåÐÅÏ¢£¬£¬£¬£¬£¬£¬Çë²ÎÔÄCVE-2018-1000888¡£¡£¡£¡£¡£¡£¡£
·ì϶ÀûÓÃ
Ŀǰ£¬£¬£¬£¬£¬£¬ÓÐÀûÓÃCVE-2018-1000888µÄEXP: https://www.anquanke.com/vul/id/1450307¡£¡£¡£¡£¡£¡£¡£
½¨¸´½¨Ò飺
DrupalÒÑÔÚÆä×îа汾½¨²¹ÁËÕâÁ½¸ö·ì϶£º
Drupal 8.6.xÉý¼¶µ½ Drupal 8.6.6.
Drupal 8.5.x Éý¼¶µ½Drupal 8.5.9.
Drupal 7.xÉý¼¶µ½Drupal 7.62.
8.5.x֮ǰµÄDrupal 8°æ±¾½«²»Ôٽӹܰ²È«¸üУ¬£¬£¬£¬£¬£¬ÓÉÓÚËüÃÇÒѾ´ïµ½Ê¹ÓÃÊÙÃü¡£¡£¡£¡£¡£¡£¡£
²Î¿¼Á´½Ó£º
https://www.drupal.org/sa-core-2019-001
https://www.drupal.org/sa-core-2019-002
http://blog.pear.php.net/2018/12/20/security-vulnerability-announcement-archive_tar/


¾©¹«Íø°²±¸11010802024551ºÅ