Drupal released security updates for Drupal 7, 8.5 and 8.6 that address two critical security vulnerabilities that could be exploited for arbitrary code execution. The first vulnerability resides in the phar stream wrapper implemented in PHP and is related to the way it handles untrusted phar : // URIs. The second flaw affects the PEAR Archive_Tar, a third-party library that handles.tar files in PHP. An attacker could use a specially crafted.tar file to delete arbitrary files on the system and possibly even execute remote code.”]
Source: https://securityaffairs.co/wordpress/80001/security/drupal-critical-flaws.html