Denial of service in Drupal - CVE-2014-9016
Published: September 14, 2016 / Updated: September 14, 2018
Vulnerability identifier: #VU444
CSH Severity: Low
CVSS v4: 6.9 [CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:N/VI:N/VA:L/SC:N/SI:N/SA:N]
CVE-ID: CVE-2014-9016
CWE-ID: CWE-284
Exploitation vector: Remote access
Exploit availability:
Public exploit is available
Vulnerability details
The vulnerability allows a remote user to cause denial of service on the target system.
The weakness exists due to CPU and memory exhaustion. Specially crafted and sent by the attackers requests may lead to site unavailability.
Successful exploitation of this vulnerability may result in denial of service on the vulnerable system.
The weakness exists due to CPU and memory exhaustion. Specially crafted and sent by the attackers requests may lead to site unavailability.
Successful exploitation of this vulnerability may result in denial of service on the vulnerable system.
Affected software
Drupal
Arch Linux
Debian Linux
Fedora
drupal7
Arch Linux
Debian Linux
Fedora
drupal7
How to mitigate CVE-2014-9016
drupal7 - addressed in versions 7.34-1.el5, 7.34-1.el6, 7.34-1.el7, 7.34-1.fc21