CVE-2014-9016: Medium severity drupal vulnerability
The password hashing API in Drupal 7.x before 7.34 and the Secure Password Hashes (aka phpass) module 6.x-2.x before 6.x-2.1 for Drupal allows remote attackers to cause a denial of service (CPU and memory consumption) via a crafted request.
Affected Software
Remediation
Patch Available
Patch Available
Event History
Frequently Asked Questions
What is the severity of CVE-2014-9016?
CVE-2014-9016 is classified as a moderate severity vulnerability due to its potential to cause denial of service through excessive CPU and memory usage.
How do I fix CVE-2014-9016?
To mitigate CVE-2014-9016, update Drupal to version 7.34 or later, or update the Secure Password Hashes module to version 6.x-2.1 or later.
What systems are affected by CVE-2014-9016?
CVE-2014-9016 affects Drupal versions earlier than 7.34 and the Secure Password Hashes module versions earlier than 6.x-2.1.
Can CVE-2014-9016 lead to data breaches?
While CVE-2014-9016 primarily leads to denial of service, it does not directly allow for data breaches but can cause service disruption.
Are there any workarounds for CVE-2014-9016?
There are no specific workarounds for CVE-2014-9016; the recommended action is to update the affected software versions.