I didn't see this mentioned in the security announcement that came out recently: http://drupal.org/drupal-6.10 and was wondering if somebody could clarify this.

My system is hosted on a linux system, so does that mean I do not need to upgrade immediately? I'm really hoping not, because I have so many drupal installations running...

Comments

gbrussel’s picture

From this page, here's a quote:

This vulnerability exists on Windows, regardless of the type of webserver (Apache, IIS) used.

So, you should upgrade if at all possible, regardless of which server the installation is running on.

stoptime’s picture

My understanding is that this pertains to a Windows server vulnerability. If you are on a Linux server, you should be OK (but always a good idea to upgrade when you can).

smithaa02’s picture

That's what I thought as well. Anybody else know for sure?