Softpedia
 

NEWS CATEGORIES:



NEWS ARCHIVE >>
SOFTPEDIA REVIEWS >>
MEET THE EDITORS >>
TRENDING TODAY
Home > News > Security > Security Blog

February 21st, 2013, 09:23 GMT · By

BLOG

Drupal 7.20 Released to Address DOS Vulnerability

SHARE:

Adjust text size:


Drupal 7.20 released Enlarge picture - Drupal 7.20 released
Drupal 7.20 has been released to fix a critical remotely-exploitable denial-of-service (DOS) vulnerability.

According to the developers, the latest update doesn’t include any new features or non-security-related fixes, but all users of Drupal 7.x are advised to install the latest version to prevent potential cybercriminal operations.

“Drupal core's Image module allows for the on-demand generation of image derivatives. This capability can be abused by requesting a large number of new derivatives which can fill up the server disk space, and which can cause a very high CPU load,” the vulnerability advisory released by Drupal reads.

It notes, “Either of these effects may lead to the site becoming unavailable or unresponsive.”

A CVE identifier has been requested for the flaw and it will be added once it’s issued.

Drupal is available for download here

TELL US WHAT YOU THINK:

1,067 hits · Link to this article · Print article · Send to friend · Subscribe to news

MUST-READ RELATED ARTICLES:


Adobe Updates Reader X, XI and 9.5.3 to Address Zero-Day Vulnerabilities

Django 1.3.6, Django 1.4.4, and Django 1.5 RC 2 Released to Address Security Issues

Oracle Updates February CPU, Fixes 5 Additional Java Vulnerabilities

Experts Identify iOS 6.1 Password Lock Bypass Vulnerability – Video (Updated)

Adobe to Patch Reader and Acrobat Zero-Day During the Week of February 18

READER COMMENTS:



No user comments yet.
Be the first to express your opinion!
Copyright © 2001-2013 Softpedia. Contact/Tip us at

WindowsGamesDriversMacLinuxScriptsMobileHandheldNews

SUBMIT PROGRAM   |   ADVERTISE   |   GET HELP   |   SEND US FEEDBACK   |   RSS FEEDS   |   UPDATE YOUR SOFTWARE   |   ROMANIAN FORUM