PT-2012-6085 · Drupal · Hotblocks

Justin C. Klein Keane

·

Published

2012-11-01

·

Updated

2012-11-01

·

CVE-2012-5704

CVSS v2.0

3.5

Low

VectorAV:N/AC:M/Au:S/C:N/I:N/A:P
Name of the Vulnerable Software and Affected Versions Hotblocks module versions 6.x-1.x before 6.x-1.8
Description The issue allows remote authenticated users with the "administer hotblocks" permission to cause a denial of service. This can be achieved by creating a block that references itself, leading to an infinite loop and time out.
Recommendations For Hotblocks module versions 6.x-1.x before 6.x-1.8, update to version 6.x-1.8 or later to resolve the issue. As a temporary workaround, consider restricting the "administer hotblocks" permission to trusted users or disabling the Hotblocks module until the update is applied.

Exploit

Fix

Found an issue in the description? Have something to add? Feel free to write us 👾

Weakness Enumeration

Related Identifiers

CVE-2012-5704

Affected Products

Hotblocks