Vulnerability Description
In Drupal Core versions 7.x prior to 7.62, 8.6.x prior to 8.6.6 and 8.5.x prior to 8.5.9; Drupal core uses the third-party PEAR Archive_Tar library. This library has released a security update which impacts some Drupal configurations. Refer to CVE-2018-1000888 for details
CVSS Score
HIGH
Affected Products
| Vendor | Product | Versions |
|---|---|---|
| Drupal | Drupal | >= 7.0, < 7.62 |
| Debian | Debian Linux | 8.0 |
Related Weaknesses (CWE)
References
- http://www.securityfocus.com/bid/106706Third Party Advisory
- https://lists.debian.org/debian-lts-announce/2019/02/msg00032.htmlMailing ListThird Party Advisory
- https://www.debian.org/security/2019/dsa-4370Third Party Advisory
- https://www.drupal.org/sa-core-2019-001PatchVendor Advisory
- http://www.securityfocus.com/bid/106706Third Party Advisory
- https://lists.debian.org/debian-lts-announce/2019/02/msg00032.htmlMailing ListThird Party Advisory
- https://www.debian.org/security/2019/dsa-4370Third Party Advisory
- https://www.drupal.org/sa-core-2019-001PatchVendor Advisory
FAQ
What is CVE-2019-6338?
CVE-2019-6338 is a vulnerability with a CVSS score of 8.0 (HIGH). In Drupal Core versions 7.x prior to 7.62, 8.6.x prior to 8.6.6 and 8.5.x prior to 8.5.9; Drupal core uses the third-party PEAR Archive_Tar library. This library has released a security update which i...
How severe is CVE-2019-6338?
CVE-2019-6338 has been rated HIGH with a CVSS base score of 8.0/10. Review the CVSS metrics above for detailed severity breakdown.
Is there a patch for CVE-2019-6338?
Check the references section above for vendor advisories and patch information. Affected products include: Drupal Drupal, Debian Debian Linux.