CVE-2012-1588: Low severity Drupal Drupal vulnerability
Published Oct 1, 2012
·Updated
Algorithmic complexity vulnerability in the filterurl function in the text filtering system (modules/filter/filter.module) in Drupal 7.x before 7.14 allows remote authenticated users with certain roles to cause a denial of service (CPU consumption) via a long email address.
Affected Software
30 affected components
Drupal Drupal=7.0
Drupal Drupal=7.0-alpha1
Drupal Drupal=7.0-alpha2
Drupal Drupal=7.0-alpha3
Drupal Drupal=7.0-alpha4
Drupal Drupal=7.0-alpha5
Drupal Drupal=7.0-alpha6
Drupal Drupal=7.0-alpha7
Drupal Drupal=7.0-beta1
Drupal Drupal=7.0-beta2
Drupal Drupal=7.0-beta3
Drupal Drupal=7.0-dev
Drupal Drupal=7.0-rc1
Drupal Drupal=7.0-rc2
Drupal Drupal=7.0-rc3
Drupal Drupal=7.0-rc4
Drupal Drupal=7.1
Drupal Drupal=7.2
Drupal Drupal=7.3
Drupal Drupal=7.4
Drupal Drupal=7.5
Drupal Drupal=7.6
Drupal Drupal=7.7
Drupal Drupal=7.8
Drupal Drupal=7.9
Drupal Drupal=7.10
Drupal Drupal=7.11
Drupal Drupal=7.12
Drupal Drupal=7.13
Drupal Drupal=7.x-dev
Remediation
Patch Available
Event History
Oct 1, 2012
CVE Published
via MITRE·12:00 AM
Data Sourced
via MITRE·12:00 AM
Description
Frequently Asked Questions
1
What is the severity of CVE-2012-1588?
CVE-2012-1588 is classified as a medium severity vulnerability due to its potential to cause a denial of service.
2
How do I fix CVE-2012-1588?
To fix CVE-2012-1588, you should update your Drupal installation to version 7.14 or later.
3
What types of users are affected by CVE-2012-1588?
CVE-2012-1588 affects remote authenticated users with specific roles who can exploit the vulnerability.
4
What component of Drupal is impacted by CVE-2012-1588?
CVE-2012-1588 impacts the _filter_url function within the text filtering system of Drupal.
5
Is there a specific version of Drupal where CVE-2012-1588 is present?
CVE-2012-1588 is present in Drupal versions 7.x before 7.14.