CVE-2019-6338
22.01.2019, 14:29
In Drupal Core versions 7.x prior to 7.62, 8.6.x prior to 8.6.6 and 8.5.x prior to 8.5.9; Drupal core uses the third-party PEAR Archive_Tar library. This library has released a security update which impacts some Drupal configurations. Refer to CVE-2018-1000888 for detailsEnginsight
Vendor | Product | Version |
---|---|---|
drupal | drupal | 7.0 ≤ 𝑥 < 7.62 |
drupal | drupal | 8.5.0 ≤ 𝑥 < 8.5.9 |
drupal | drupal | 8.6.0 ≤ 𝑥 < 8.6.6 |
debian | debian_linux | 8.0 |
debian | debian_linux | 9.0 |
𝑥
= Vulnerable software versions

Ubuntu Releases
Common Weakness Enumeration
References