Drupal Multiple Vulnerabilities
RISK: Medium Risk
TYPE: Servers - Web Servers
Two vulnerabilities have been identified in Drupal, which can be exploited by malicious people to cause a DoS (Denial of Service).
1) An error in xmlrpc.php when expanding entity references and can be exploited to consume large amounts of memory and cause an hang via a specially crafted XML file containing malicious attributes.
2) An error related to the OpenID module when expanding entity references and can be exploited to consume large amounts of memory and cause an hang via a specially crafted XML file containing malicious attributes.
Impact
- Denial of Service
System / Technologies affected
- Drupal core 6.x versions prior to 6.33.
- Drupal core 7.x versions prior to 7.31.
Solutions
Before installation of the software, please visit the software manufacturer web-site for more details.
- Upgrade to version 6.33 for Drupal 6.x
- Upgrade to version 7.31 for Drupal 7.x.
Vulnerability Identifier
- No CVE information is available
Source
Related Link
Share with