The password hashing API in Drupal 7.x before 7.34 and the Secure Password Hashes (aka phpass) module 6.x-2.x before 6.x-2.1 for Drupal allows remote attackers to cause a denial of service (CPU and memory consumption) via a crafted request.
2014-11-24T15:59:17.920
2025-04-12T10:46:40.837
Deferred
CVSSv2: 5.0 (MEDIUM)
AV:N/AC:L/Au:N/C:N/I:N/A:P
10.0
2.9
Type | Vendor | Product | Version/Range | Vulnerable? |
---|---|---|---|---|
Application | drupal | drupal | < 7.34 | Yes |
Application | secure_password_hashes_project | secure_passwords_hashes | < 6.x-2.1 | Yes |
Operating System | debian | debian_linux | 7.0 | Yes |