Drupal Multiple Vulerabilities
Last Update Date:
25 Nov 2014 10:47
Release Date:
25 Nov 2014
3543
Views
RISK: Medium Risk
TYPE: Servers - Web Servers
Two vulnerabilities were identified in Drupal.
A remote user can send a specially crafted request to gain access to another user's session.
A remote user can send specially crafted data to the password hashing API to consume excessive memory and CPU resources, causing the target site to become unavailable or unresponsive. Only version 7.x is affected.
Impact
- Denial of Service
- Security Restriction Bypass
System / Technologies affected
- Versions prior to 6.34
- Versions prior to 7.34
Solutions
Before installation of the software, please visit the software manufacturer web-site for more details.
- The vendor has issued a fix (6.34, 7.34).
Vulnerability Identifier
Source
Related Link
Share with