MGASA-2014-0329
Dashboard / Vulnerabilities / MGASA-2014-0329
MGASA-2014-0329
Summary: Updated drupal packages fix security vulnerability
Details: A denial of service issue exists in Drupal before 7.31, due to XML entity expansion in a publicly accessible XML-RPC endpoint. The drupal package has been updated to version 7.31 to fix this issue and other bugs. See the upstream advisory and release notes for more details.
References: https://advisories.mageia.org/MGASA-2014-0329.html, https://bugs.mageia.org/show_bug.cgi?id=13876, https://www.debian.org/security/2014/dsa-2999, https://www.drupal.org/SA-CORE-2014-004, https://www.drupal.org/drupal-7.30, https://www.drupal.org/drupal-7.30-release-notes, https://www.drupal.org/drupal-7.31, https://www.drupal.org/drupal-7.31-release-notes
Affected packages
Package
Name: drupal
Purl: pkg:rpm/mageia/drupal?arch=source&distro=mageia-3
Affected ranges
Type: ECOSYSTEM
Events:
