Drupal Á½¸öí§Òâ´úÂëÖ´ÐÐÎó²îÇ徲ͨ¸æ
Ðû²¼Ê±¼ä 2019-01-18Îó²î±àºÅºÍ¼¶±ð
ÔÝÎÞ ÑÏÖØ CVSS·ÖÖµ£º¹Ù·½Î´ÆÀ¶¨
ÔÝÎÞ ÑÏÖØ CVSS·ÖÖµ£º¹Ù·½Î´ÆÀ¶¨
Ó°Ïì°æ±¾
Drupal 8.6.x.
Drupal 8.5.x.
Drupal 7.x.
Îó²î¸ÅÊö
1ÔÂ17ÈÕ£¬£¬£¬£¬£¬£¬DrupalÐû²¼ÁËDrupal 7,8.5ºÍ8.6µÄÇå¾²¸üУ¬£¬£¬£¬£¬£¬½â¾öÁËÁ½¸ö¿ÉÄܱ»Ê¹ÓÃÀ´Ö´ÐÐí§Òâ´úÂëµÄ¡°Òªº¦¡±Çå¾²Îó²î¡£¡£¡£¡£
Ô¶³Ì¹¥»÷Õß¿ÉÒÔʹÓõÚÒ»¸öÎó²îÀ´Ö´ÐÐí§ÒâPHP´úÂë¡£¡£¡£¡£¸ÃÎó²î±£´æÓÚPHPÖÐʵÏÖµÄpharÁ÷°ü×°ÖУ¬£¬£¬£¬£¬£¬Óë´¦Öóͷ£²»ÊÜÐÅÈεÄphar:// URIµÄ·½·¨Óйء£¡£¡£¡£
һЩDrupal´úÂë¿ÉÄÜÔÚ¶ÔûÓоÓɳä·ÖÑéÖ¤µÄÓû§ÊäÈëÖ´ÐÐÎļþ²Ù×÷£¬£¬£¬£¬£¬£¬´Ó¶øÌ»Â¶ÓÚ´ËÎó²î¡£¡£¡£¡£
´úÂë·¾¶Í¨³£ÐèÒª»á¼ûÖÎÀíȨÏÞ»ò·Çµä·¶ÉèÖ㬣¬£¬£¬£¬£¬´Ó¶ø¼õÇáÁË´ËÎó²î¡£¡£¡£¡£
µÚ¶þ¸öÎó²îÓ°ÏìÁËPEAR Archive_Tar£¬£¬£¬£¬£¬£¬ÕâÊÇÒ»¸öÓÃPHP´¦Öóͷ£.tarÎļþµÄµÚÈý·½¿â¡£¡£¡£¡£¹¥»÷Õß¿ÉÒÔʹÓÃÌØÖÆµÄ.tarÎļþɾ³ýϵͳÉϵÄí§ÒâÎļþ£¬£¬£¬£¬£¬£¬ÉõÖÁ¿ÉÄÜÖ´ÐÐÔ¶³Ì´úÂë¡£¡£¡£¡£¸Ã¿âÐû²¼ÁËÒ»¸öÇå¾²¸üУ¬£¬£¬£¬£¬£¬Ëü»áÓ°ÏìһЩDrupalÉèÖᣡ£¡£¡£ÓйØÏêϸÐÅÏ¢£¬£¬£¬£¬£¬£¬Çë²ÎÔÄCVE-2018-1000888¡£¡£¡£¡£
Îó²îʹÓÃ
ÏÖÔÚ£¬£¬£¬£¬£¬£¬ÓÐʹÓÃCVE-2018-1000888µÄEXP: https://www.anquanke.com/vul/id/1450307¡£¡£¡£¡£
ÐÞ¸´½¨Ò飺
DrupalÒÑÔÚÆä×îа汾ÐÞ²¹ÁËÕâÁ½¸öÎó²î£º
Drupal 8.6.xÉý¼¶µ½ Drupal 8.6.6.
Drupal 8.5.x Éý¼¶µ½Drupal 8.5.9.
Drupal 7.xÉý¼¶µ½Drupal 7.62.
8.5.x֮ǰµÄDrupal 8°æ±¾½«²»ÔÙÎüÊÕÇå¾²¸üУ¬£¬£¬£¬£¬£¬ÓÉÓÚËüÃÇÒѾµÖ´ïʹÓÃÊÙÃü¡£¡£¡£¡£
²Î¿¼Á´½Ó£º
https://www.drupal.org/sa-core-2019-001
https://www.drupal.org/sa-core-2019-002
http://blog.pear.php.net/2018/12/20/security-vulnerability-announcement-archive_tar/


¾©¹«Íø°²±¸11010802024551ºÅ