Denial of service in Drupal - CVE-2014-9016

 

Denial of service in Drupal - CVE-2014-9016

Published: September 14, 2016 / Updated: September 14, 2018


Vulnerability identifier: #VU444
CSH Severity: Low
CVSS v4: 6.9 [CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:N/VI:N/VA:L/SC:N/SI:N/SA:N]
CVE-ID: CVE-2014-9016
CWE-ID: CWE-284
Exploitation vector: Remote access
Exploit availability: Public exploit is available

Vulnerability details

The vulnerability allows a remote user to cause denial of service on the target system.
The weakness exists due to CPU and memory exhaustion. Specially crafted and sent by the attackers requests may lead to site unavailability.
Successful exploitation of this vulnerability may result in denial of service on the vulnerable system.

Affected software

Drupal
Arch Linux
Debian Linux
Fedora
drupal7

How to mitigate CVE-2014-9016


drupal7 - addressed in versions 7.34-1.el5, 7.34-1.el6, 7.34-1.el7, 7.34-1.fc21

Links to Public Exploits and PoC-codes

External References

Related Security Bulletins