Drupal Á½¸öí§Òâ´úÂëÖ´ÐÐÎó²îÇ徲ͨ¸æ
Ðû²¼Ê±¼ä 2019-01-18Îó²î±àºÅºÍ¼¶±ð
ÔÝÎÞ ÑÏÖØ CVSS·ÖÖµ£º¹Ù·½Î´ÆÀ¶¨
ÔÝÎÞ ÑÏÖØ CVSS·ÖÖµ£º¹Ù·½Î´ÆÀ¶¨
Ó°Ïì°æ±¾
Drupal 8.6.x.
Drupal 8.5.x.
Drupal 7.x.
Îó²î¸ÅÊö
1ÔÂ17ÈÕ£¬£¬£¬£¬£¬£¬£¬£¬DrupalÐû²¼ÁËDrupal 7,8.5ºÍ8.6µÄÇå¾²¸üУ¬£¬£¬£¬£¬£¬£¬£¬½â¾öÁËÁ½¸ö¿ÉÄܱ»Ê¹ÓÃÀ´Ö´ÐÐí§Òâ´úÂëµÄ¡°Òªº¦¡±Çå¾²Îó²î¡£¡£¡£¡£¡£¡£
Ô¶³Ì¹¥»÷Õß¿ÉÒÔʹÓõÚÒ»¸öÎó²îÀ´Ö´ÐÐí§ÒâPHP´úÂë¡£¡£¡£¡£¡£¡£¸ÃÎó²î±£´æÓÚPHPÖÐʵÏÖµÄpharÁ÷°ü×°ÖУ¬£¬£¬£¬£¬£¬£¬£¬Óë´¦Öóͷ£²»ÊÜÐÅÈεÄphar:// URIµÄ·½·¨Óйء£¡£¡£¡£¡£¡£
һЩDrupal´úÂë¿ÉÄÜÔÚ¶ÔûÓоÓɳä·ÖÑéÖ¤µÄÓû§ÊäÈëÖ´ÐÐÎļþ²Ù×÷£¬£¬£¬£¬£¬£¬£¬£¬´Ó¶øÌ»Â¶ÓÚ´ËÎó²î¡£¡£¡£¡£¡£¡£
´úÂë·¾¶Í¨³£ÐèÒª»á¼ûÖÎÀíȨÏÞ»ò·Çµä·¶ÉèÖ㬣¬£¬£¬£¬£¬£¬£¬´Ó¶ø¼õÇáÁË´ËÎó²î¡£¡£¡£¡£¡£¡£
µÚ¶þ¸öÎó²îÓ°ÏìÁËPEAR Archive_Tar£¬£¬£¬£¬£¬£¬£¬£¬ÕâÊÇÒ»¸öÓÃPHP´¦Öóͷ£.tarÎļþµÄµÚÈý·½¿â¡£¡£¡£¡£¡£¡£¹¥»÷Õß¿ÉÒÔʹÓÃÌØÖÆµÄ.tarÎļþɾ³ýϵͳÉϵÄí§ÒâÎļþ£¬£¬£¬£¬£¬£¬£¬£¬ÉõÖÁ¿ÉÄÜÖ´ÐÐÔ¶³Ì´úÂë¡£¡£¡£¡£¡£¡£¸Ã¿âÐû²¼ÁËÒ»¸öÇå¾²¸üУ¬£¬£¬£¬£¬£¬£¬£¬Ëü»áÓ°ÏìһЩDrupalÉèÖᣡ£¡£¡£¡£¡£ÓйØÏêϸÐÅÏ¢£¬£¬£¬£¬£¬£¬£¬£¬Çë²ÎÔÄCVE-2018-1000888¡£¡£¡£¡£¡£¡£
Îó²îʹÓÃ
ÏÖÔÚ£¬£¬£¬£¬£¬£¬£¬£¬ÓÐʹÓÃCVE-2018-1000888µÄEXP: https://www.anquanke.com/vul/id/1450307¡£¡£¡£¡£¡£¡£
ÐÞ¸´½¨Ò飺
DrupalÒÑÔÚÆä×îа汾ÐÞ²¹ÁËÕâÁ½¸öÎó²î£º
Drupal 8.6.xÉý¼¶µ½ Drupal 8.6.6.
Drupal 8.5.x Éý¼¶µ½Drupal 8.5.9.
Drupal 7.xÉý¼¶µ½Drupal 7.62.
8.5.x֮ǰµÄDrupal 8°æ±¾½«²»ÔÙÎüÊÕÇå¾²¸üУ¬£¬£¬£¬£¬£¬£¬£¬ÓÉÓÚËüÃÇÒѾµÖ´ïʹÓÃÊÙÃü¡£¡£¡£¡£¡£¡£
²Î¿¼Á´½Ó£º
https://www.drupal.org/sa-core-2019-001
https://www.drupal.org/sa-core-2019-002
http://blog.pear.php.net/2018/12/20/security-vulnerability-announcement-archive_tar/


¾©¹«Íø°²±¸11010802024551ºÅ