Gentoo Websites Logo
Go to: Gentoo Home Documentation Forums Lists Bugs Planet Store Wiki Get Gentoo!
Bug 534678 - <www-apps/drupal-{6.34,7.34}: DoS and session hijack vulnerabilities (CVE-2014-{9015,9016})
Summary: <www-apps/drupal-{6.34,7.34}: DoS and session hijack vulnerabilities (CVE-201...
Status: RESOLVED FIXED
Alias: None
Product: Gentoo Security
Classification: Unclassified
Component: Vulnerabilities (show other bugs)
Hardware: All Linux
: Normal trivial (vote)
Assignee: Gentoo Security
URL:
Whiteboard: ~3 [noglsa]
Keywords:
Depends on:
Blocks:
 
Reported: 2015-01-04 18:02 UTC by GLSAMaker/CVETool Bot
Modified: 2015-01-04 18:04 UTC (History)
1 user (show)

See Also:
Package list:
Runtime testing required: ---


Attachments

Note You need to log in before you can comment on or make changes to this bug.
Description GLSAMaker/CVETool Bot gentoo-dev 2015-01-04 18:02:30 UTC
CVE-2014-9016 (http://nvd.nist.gov/nvd.cfm?cvename=CVE-2014-9016):
  The password hashing API in Drupal 7.x before 7.34 and the Secure Password
  Hashes (aka phpass) module 6.x-2.x before 6.x-2.1 for Drupal allows remote
  attackers to cause a denial of service (CPU and memory consumption) via a
  crafted request.

CVE-2014-9015 (http://nvd.nist.gov/nvd.cfm?cvename=CVE-2014-9015):
  Drupal 6.x before 6.34 and 7.x before 7.34 allows remote attackers to hijack
  sessions via a crafted request, as demonstrated by a crafted request to a
  server that supports both HTTP and HTTPS sessions.
Comment 1 Sean Amoss (RETIRED) gentoo-dev Security 2015-01-04 18:04:28 UTC
Tracking bug for CVEs. Versions were already bumped by maintainers and vulnerable versions were dropped.

Closing noglsa for ~arch only.