CERT mailing list archives

Drupal Releases Security Advisory


From: "US-CERT" <US-CERT () ncas us-cert gov>
Date: Fri, 17 Oct 2014 09:08:30 -0500

NCCIC / US-CERT

National Cyber Awareness System:

Drupal Releases Security Advisory [ 
https://www.us-cert.gov/ncas/current-activity/2014/10/17/Drupal-Releases-Security-Advisory ] 10/17/2014 09:11 AM EDT 
Original release date: October 17, 2014

Drupal has released a security advisory to address an application program interface (API) vulnerability (CVE-2014-3704 
[ http://web.nvd.nist.gov/view/vuln/detail?vulnId=CVE-2014-3704 ]) that could allow an attacker to execute arbitrary 
SQL commands on an affected system.

This vulnerability affects all Drupal core 7.x versions prior to 7.32.

US-CERT advises users and administrators review Drupal's Security Advisory [ https://www.drupal.org/SA-CORE-2014-005 ] 
and apply the necessary update or patch.

________________________________________________________________________

This product is provided subject to this Notification [ http://www.us-cert.gov/privacy/notification ] and this Privacy 
& Use [ http://www.us-cert.gov/privacy/ ] policy.

________________________________________________________________________

OTHER RESOURCES: Contact Us [ http://www.us-cert.gov/contact-us/ ] | Security Publications [ 
http://www.us-cert.gov/security-publications ] | Alerts and Tips [ http://www.us-cert.gov/ncas ] | Related Resources [ 
http://www.us-cert.gov/related-resources ] 

STAY CONNECTED: Sign up for email updates [ http://public.govdelivery.com/accounts/USDHSUSCERT/subscriber/new ] 


Current thread: