Back to search
CVE-2014-9016
Published: Nov 24, 2014
Modified: Aug 6, 2024
PUBLISHED
Description
The password hashing API in Drupal 7.x before 7.34 and the Secure Password Hashes (aka phpass) module 6.x-2.x before 6.x-2.1 for Drupal allows remote attackers to cause a denial of service (CPU and memory consumption) via a crafted request.
| Vendor | Product | Versions |
|---|---|---|
n/a | n/a | affected n/a |
References
https://www.drupal.org/node/2378375
x_refsource_CONFIRM
[oss-security] 20141120 Pending CVE assignments for SA-CORE-2014-006?
mailing-list
x_refsource_MLIST
https://www.drupal.org/SA-CORE-2014-006
x_refsource_CONFIRM
[oss-security] 20141120 Re: [security] Pending CVE assignments for SA-CORE-2014-006?
mailing-list
x_refsource_MLIST
59164
third-party-advisory
x_refsource_SECUNIA
https://www.drupal.org/node/2378367
x_refsource_MISC
[oss-security] 20141120 Re: [security] Pending CVE assignments for SA-CORE-2014-006?
mailing-list
x_refsource_MLIST
59814
third-party-advisory
x_refsource_SECUNIA
DSA-3075
vendor-advisory
x_refsource_DEBIAN
Security Training
Train your team to recognize and prevent security threats with our comprehensive security awareness program.
Start TrainingVulnerability Scanning
Discover vulnerabilities in your applications and infrastructure before attackers do.
Scan Now