CVE-2013-0316: Medium severity Drupal Drupal vulnerability
Published Mar 27, 2013
·Updated
The Image module in Drupal 7.x before 7.20 allows remote attackers to cause a denial of service (CPU and disk space consumption) via a large number of new derivative requests.
Affected Software
36 affected components
Drupal Drupal=7.0
Drupal Drupal=7.0-alpha1
Drupal Drupal=7.0-alpha2
Drupal Drupal=7.0-alpha3
Drupal Drupal=7.0-alpha4
Drupal Drupal=7.0-alpha5
Drupal Drupal=7.0-alpha6
Drupal Drupal=7.0-alpha7
Drupal Drupal=7.0-beta1
Drupal Drupal=7.0-beta2
Drupal Drupal=7.0-beta3
Drupal Drupal=7.0-dev
Drupal Drupal=7.0-rc1
Drupal Drupal=7.0-rc2
Drupal Drupal=7.0-rc3
Drupal Drupal=7.0-rc4
Drupal Drupal=7.1
Drupal Drupal=7.2
Drupal Drupal=7.3
Drupal Drupal=7.4
Drupal Drupal=7.5
Drupal Drupal=7.6
Drupal Drupal=7.7
Drupal Drupal=7.8
Drupal Drupal=7.9
Drupal Drupal=7.10
Drupal Drupal=7.11
Drupal Drupal=7.12
Drupal Drupal=7.13
Drupal Drupal=7.14
Drupal Drupal=7.15
Drupal Drupal=7.16
Drupal Drupal=7.17
Drupal Drupal=7.18
Drupal Drupal=7.19
Drupal Drupal=7.x-dev
Remediation
Patch Available
Event History
Mar 27, 2013
CVE Published
via MITRE·09:00 PM
Data Sourced
via MITRE·09:00 PM
Description
Frequently Asked Questions
1
What is the severity of CVE-2013-0316?
CVE-2013-0316 is a medium-severity vulnerability that can lead to denial of service through excessive resource consumption.
2
How do I fix CVE-2013-0316?
To mitigate CVE-2013-0316, update your Drupal installation to version 7.20 or later.
3
What versions of Drupal are affected by CVE-2013-0316?
CVE-2013-0316 affects Drupal 7.x versions prior to 7.20.
4
What type of attack does CVE-2013-0316 enable?
CVE-2013-0316 enables remote attackers to perform denial of service attacks by creating numerous derivative image requests.
5
Is CVE-2013-0316 a remote or local vulnerability?
CVE-2013-0316 is a remote vulnerability that can be exploited by attackers without local access.