Skip to main content

Drupal Multiple Vulnerabilities

Last Update Date: 8 Aug 2014 12:12 Release Date: 8 Aug 2014 4062 Views

RISK: Medium Risk

TYPE: Servers - Web Servers

TYPE: Web Servers

Two vulnerabilities have been identified in Drupal, which can be exploited by malicious people to cause a DoS (Denial of Service).

 

1) An error in xmlrpc.php when expanding entity references and can be exploited to consume large amounts of memory and cause an hang via a specially crafted XML file containing malicious attributes.

 

2) An error related to the OpenID module when expanding entity references and can be exploited to consume large amounts of memory and cause an hang via a specially crafted XML file containing malicious attributes.


Impact

  • Denial of Service

System / Technologies affected

  • Drupal core 6.x versions prior to 6.33.
  • Drupal core 7.x versions prior to 7.31.

 


Solutions

Before installation of the software, please visit the software manufacturer web-site for more details.

  • Upgrade to version 6.33 for Drupal 6.x
  • Upgrade to version 7.31 for Drupal 7.x.

Vulnerability Identifier

  • No CVE information is available

Source


Related Link