Drupal Á½¸öí§Òâ´úÂëÖ´ÐÐÎó²îÇ徲ͨ¸æ
Ðû²¼Ê±¼ä 2019-01-18Îó²î±àºÅºÍ¼¶±ð
ÔÝÎÞ ÑÏÖØ CVSS·ÖÖµ£º¹Ù·½Î´ÆÀ¶¨
ÔÝÎÞ ÑÏÖØ CVSS·ÖÖµ£º¹Ù·½Î´ÆÀ¶¨
Ó°Ïì°æ±¾
Drupal 8.6.x.
Drupal 8.5.x.
Drupal 7.x.
Îó²î¸ÅÊö
1ÔÂ17ÈÕ£¬DrupalÐû²¼ÁËDrupal 7,8.5ºÍ8.6µÄÇå¾²¸üУ¬½â¾öÁËÁ½¸ö¿ÉÄܱ»Ê¹ÓÃÀ´Ö´ÐÐí§Òâ´úÂëµÄ¡°Òªº¦¡±Çå¾²Îó²î¡£
Ô¶³Ì¹¥»÷Õß¿ÉÒÔʹÓõÚÒ»¸öÎó²îÀ´Ö´ÐÐí§ÒâPHP´úÂë¡£¸ÃÎó²î±£´æÓÚPHPÖÐʵÏÖµÄpharÁ÷°ü×°ÖУ¬Óë´¦Öóͷ£²»ÊÜÐÅÍеÄphar:// URIµÄ·½·¨Óйء£
һЩDrupal´úÂë¿ÉÄÜÔÚ¶ÔûÓоÓɳä·ÖÑéÖ¤µÄÓû§ÊäÈëÖ´ÐÐÎļþ²Ù×÷£¬´Ó¶øÌ»Â¶ÓÚ´ËÎó²î¡£
´úÂë·¾¶Í¨³£ÐèÒª»á¼ûÖÎÀíȨÏÞ»ò·Çµä·¶ÉèÖ㬴Ӷø¼õÇáÁË´ËÎó²î¡£
µÚ¶þ¸öÎó²îÓ°ÏìÁËPEAR Archive_Tar£¬ÕâÊÇÒ»¸öÓÃPHP´¦Öóͷ£.tarÎļþµÄµÚÈý·½¿â¡£¹¥»÷Õß¿ÉÒÔʹÓÃÌØÖÆµÄ.tarÎļþɾ³ýϵͳÉϵÄí§ÒâÎļþ£¬ÉõÖÁ¿ÉÄÜÖ´ÐÐÔ¶³Ì´úÂë¡£¸Ã¿âÐû²¼ÁËÒ»¸öÇå¾²¸üУ¬Ëü»áÓ°ÏìһЩDrupalÉèÖá£ÓйØÏêϸÐÅÏ¢£¬Çë²ÎÔÄCVE-2018-1000888¡£
Îó²îʹÓÃ
ÏÖÔÚ£¬ÓÐʹÓÃCVE-2018-1000888µÄEXP: https://www.anquanke.com/vul/id/1450307¡£
ÐÞ¸´½¨Ò飺
DrupalÒÑÔÚÆä×îа汾ÐÞ²¹ÁËÕâÁ½¸öÎó²î£º
Drupal 8.6.xÉý¼¶µ½ Drupal 8.6.6.
Drupal 8.5.x Éý¼¶µ½Drupal 8.5.9.
Drupal 7.xÉý¼¶µ½Drupal 7.62.
8.5.x֮ǰµÄDrupal 8°æ±¾½«²»ÔÙÎüÊÕÇå¾²¸üУ¬ÓÉÓÚËüÃÇÒѾµÖ´ïʹÓÃÊÙÃü¡£
²Î¿¼Á´½Ó£º
https://www.drupal.org/sa-core-2019-001
https://www.drupal.org/sa-core-2019-002
http://blog.pear.php.net/2018/12/20/security-vulnerability-announcement-archive_tar/


¾©¹«Íø°²±¸11010802024551ºÅ