CERT mailing list archives
Drupal Releases Security Advisory
From: "US-CERT" <US-CERT () ncas us-cert gov>
Date: Fri, 17 Oct 2014 09:08:30 -0500
NCCIC / US-CERT National Cyber Awareness System: Drupal Releases Security Advisory [ https://www.us-cert.gov/ncas/current-activity/2014/10/17/Drupal-Releases-Security-Advisory ] 10/17/2014 09:11 AM EDT Original release date: October 17, 2014 Drupal has released a security advisory to address an application program interface (API) vulnerability (CVE-2014-3704 [ http://web.nvd.nist.gov/view/vuln/detail?vulnId=CVE-2014-3704 ]) that could allow an attacker to execute arbitrary SQL commands on an affected system. This vulnerability affects all Drupal core 7.x versions prior to 7.32. US-CERT advises users and administrators review Drupal's Security Advisory [ https://www.drupal.org/SA-CORE-2014-005 ] and apply the necessary update or patch. ________________________________________________________________________ This product is provided subject to this Notification [ http://www.us-cert.gov/privacy/notification ] and this Privacy & Use [ http://www.us-cert.gov/privacy/ ] policy. ________________________________________________________________________ OTHER RESOURCES: Contact Us [ http://www.us-cert.gov/contact-us/ ] | Security Publications [ http://www.us-cert.gov/security-publications ] | Alerts and Tips [ http://www.us-cert.gov/ncas ] | Related Resources [ http://www.us-cert.gov/related-resources ] STAY CONNECTED: Sign up for email updates [ http://public.govdelivery.com/accounts/USDHSUSCERT/subscriber/new ]
Current thread:
- Drupal Releases Security Advisory US-CERT (Oct 17)
- <Possible follow-ups>
- Drupal Releases Security Advisory US-CERT (Nov 20)