PT-2012-6085 · Drupal · Hotblocks
Justin C. Klein Keane
·
Published
2012-11-01
·
Updated
2012-11-01
·
CVE-2012-5704
CVSS v2.0
3.5
Low
| Vector | AV:N/AC:M/Au:S/C:N/I:N/A:P |
Name of the Vulnerable Software and Affected Versions
Hotblocks module versions 6.x-1.x before 6.x-1.8
Description
The issue allows remote authenticated users with the "administer hotblocks" permission to cause a denial of service. This can be achieved by creating a block that references itself, leading to an infinite loop and time out.
Recommendations
For Hotblocks module versions 6.x-1.x before 6.x-1.8, update to version 6.x-1.8 or later to resolve the issue. As a temporary workaround, consider restricting the "administer hotblocks" permission to trusted users or disabling the Hotblocks module until the update is applied.
Exploit
Fix
Found an issue in the description? Have something to add? Feel free to write us 👾
Weakness Enumeration
Related Identifiers
Affected Products
Hotblocks