Drupal Á½¸öí§Òâ´úÂëÖ´ÐÐÎó²îÇ徲ͨ¸æ

Ðû²¼Ê±¼ä 2019-01-18

Îó²î±àºÅºÍ¼¶±ð


ÔÝÎÞ ÑÏÖØ  CVSS·ÖÖµ£º¹Ù·½Î´ÆÀ¶¨

ÔÝÎÞ ÑÏÖØ  CVSS·ÖÖµ£º¹Ù·½Î´ÆÀ¶¨


Ó°Ïì°æ±¾


Drupal 8.6.x.

Drupal 8.5.x.

Drupal 7.x.


Îó²î¸ÅÊö


1ÔÂ17ÈÕ£¬£¬£¬£¬£¬£¬ £¬£¬DrupalÐû²¼ÁËDrupal 7,8.5ºÍ8.6µÄÇå¾²¸üУ¬£¬£¬£¬£¬£¬ £¬£¬½â¾öÁËÁ½¸ö¿ÉÄܱ»Ê¹ÓÃÀ´Ö´ÐÐí§Òâ´úÂëµÄ¡°Òªº¦¡±Çå¾²Îó²î¡£¡£¡£¡£¡£¡£

Ô¶³Ì¹¥»÷Õß¿ÉÒÔʹÓõÚÒ»¸öÎó²îÀ´Ö´ÐÐí§ÒâPHP´úÂë¡£¡£¡£¡£¡£¡£¸ÃÎó²î±£´æÓÚPHPÖÐʵÏÖµÄpharÁ÷°ü×°ÖУ¬£¬£¬£¬£¬£¬ £¬£¬Óë´¦Öóͷ£²»ÊÜÐÅÈεÄphar:// URIµÄ·½·¨ÓйØ¡£¡£¡£¡£¡£¡£


һЩDrupal´úÂë¿ÉÄÜÔÚ¶ÔûÓо­Óɳä·ÖÑéÖ¤µÄÓû§ÊäÈëÖ´ÐÐÎļþ²Ù×÷£¬£¬£¬£¬£¬£¬ £¬£¬´Ó¶øÌ»Â¶ÓÚ´ËÎó²î¡£¡£¡£¡£¡£¡£


´úÂë·¾¶Í¨³£ÐèÒª»á¼ûÖÎÀíȨÏÞ»ò·Çµä·¶ÉèÖ㬣¬£¬£¬£¬£¬ £¬£¬´Ó¶ø¼õÇáÁË´ËÎó²î¡£¡£¡£¡£¡£¡£


µÚ¶þ¸öÎó²îÓ°ÏìÁËPEAR Archive_Tar£¬£¬£¬£¬£¬£¬ £¬£¬ÕâÊÇÒ»¸öÓÃPHP´¦Öóͷ£.tarÎļþµÄµÚÈý·½¿â¡£¡£¡£¡£¡£¡£¹¥»÷Õß¿ÉÒÔʹÓÃÌØÖÆµÄ.tarÎļþɾ³ýϵͳÉϵÄí§ÒâÎļþ£¬£¬£¬£¬£¬£¬ £¬£¬ÉõÖÁ¿ÉÄÜÖ´ÐÐÔ¶³Ì´úÂë¡£¡£¡£¡£¡£¡£¸Ã¿âÐû²¼ÁËÒ»¸öÇå¾²¸üУ¬£¬£¬£¬£¬£¬ £¬£¬Ëü»áÓ°ÏìһЩDrupalÉèÖᣡ£¡£¡£¡£¡£ÓйØÏêϸÐÅÏ¢£¬£¬£¬£¬£¬£¬ £¬£¬Çë²ÎÔÄCVE-2018-1000888¡£¡£¡£¡£¡£¡£


Îó²îʹÓÃ


ÏÖÔÚ£¬£¬£¬£¬£¬£¬ £¬£¬ÓÐʹÓÃCVE-2018-1000888µÄEXP:  https://www.anquanke.com/vul/id/1450307¡£¡£¡£¡£¡£¡£


ÐÞ¸´½¨Ò飺


DrupalÒÑÔÚÆä×îа汾ÐÞ²¹ÁËÕâÁ½¸öÎó²î£º

Drupal 8.6.xÉý¼¶µ½ Drupal 8.6.6.

Drupal 8.5.x Éý¼¶µ½Drupal 8.5.9.

Drupal 7.xÉý¼¶µ½Drupal 7.62.

8.5.x֮ǰµÄDrupal 8°æ±¾½«²»ÔÙÎüÊÕÇå¾²¸üУ¬£¬£¬£¬£¬£¬ £¬£¬ÓÉÓÚËüÃÇÒѾ­µÖ´ïʹÓÃÊÙÃü¡£¡£¡£¡£¡£¡£


²Î¿¼Á´½Ó£º


https://www.drupal.org/sa-core-2019-001

https://www.drupal.org/sa-core-2019-002

http://blog.pear.php.net/2018/12/20/security-vulnerability-announcement-archive_tar/