Skip to main content

Drupal Multiple Vulerabilities

Last Update Date: 25 Nov 2014 10:47 Release Date: 25 Nov 2014 3004 Views

RISK: Medium Risk

TYPE: Servers - Web Servers

TYPE: Web Servers

Two vulnerabilities were identified in Drupal.

A remote user can send a specially crafted request to gain access to another user's session.

A remote user can send specially crafted data to the password hashing API to consume excessive memory and CPU resources, causing the target site to become unavailable or unresponsive. Only version 7.x is affected.


Impact

  • Denial of Service
  • Security Restriction Bypass

System / Technologies affected

  • Versions prior to 6.34
  • Versions prior to 7.34

Solutions

Before installation of the software, please visit the software manufacturer web-site for more details.

  • The vendor has issued a fix (6.34, 7.34).

Vulnerability Identifier


Source


Related Link