{"id":"CVE-2019-6338","aliases":["DRUPAL-CORE-2019-001","GHSA-6rmq-x2hv-vxpp"],"url":"https://o3.security/vulnerability/CVE-2019-6338","summary":"Drupal core third-party PEAR Archive_Tar library is vulnerable to Deserialization of Untrusted Data","details":"In Drupal Core versions 7.x prior to 7.62, 8.6.x prior to 8.6.6 and 8.5.x prior to 8.5.9; Drupal core uses the third-party PEAR Archive_Tar library. This library has released a security update which impacts some Drupal configurations. Refer to CVE-2018-1000888 for details","published":"2019-01-22T14:29:00.517Z","modified":"2026-07-08T05:55:37.515305589Z","cvss":{"score":8,"severity":"HIGH","vector":"CVSS:3.0/AV:N/AC:L/PR:L/UI:R/S:U/C:H/I:H/A:H"},"epss":null,"cisaKev":null,"exploitsKnown":null,"affectedPackages":[{"ecosystem":"Packagist","name":"drupal/drupal","fixedVersion":"7.62.0"},{"ecosystem":"Packagist","name":"drupal/drupal","fixedVersion":"8.5.9"},{"ecosystem":"Packagist","name":"drupal/drupal","fixedVersion":"8.6.6"}],"fix":null,"references":[{"type":"ADVISORY","url":"http://www.securityfocus.com/bid/106706"},{"type":"ADVISORY","url":"https://lists.debian.org/debian-lts-announce/2019/02/msg00032.html"},{"type":"ADVISORY","url":"https://www.debian.org/security/2019/dsa-4370"},{"type":"FIX","url":"https://www.drupal.org/sa-core-2019-001"}],"provenance":{"sources":["OSV.dev","FIRST.org (EPSS)"],"lastVerified":"2026-07-08T05:55:37.515305589Z"}}