CVE-2019-6338
Description
In Drupal Core versions 7.x prior to 7.62, 8.6.x prior to 8.6.6 and 8.5.x prior to 8.5.9; Drupal core uses the third-party PEAR Archive_Tar library. This library has released a security update which impacts some Drupal configurations. Refer to CVE-2018-1000888 for details
CWE
- (none)
Affected
- Drupal / Drupal core — v=7.x <7.62 [affected]; v=8.6.x <8.6.6. [affected]; v=8.5.x <8.5.9 [affected]
CVSS
- (none)
References
- https://www.drupal.org/sa-core-2019-001 x_refsource_CONFIRM
- https://www.debian.org/security/2019/dsa-4370 vendor-advisory, x_refsource_DEBIAN
- https://lists.debian.org/debian-lts-announce/2019/02/msg00032.html mailing-list, x_refsource_MLIST
- http://www.securityfocus.com/bid/106706 vdb-entry, x_refsource_BID
Source
cvelistV5-main/cves/2019/6xxx/CVE-2019-6338.json