Vulnerability Bulletins

SA-CORE-2014-004 - Drupal core - Denial of service

   
Affected software Drupal
 
Advisory ID: DRUPAL-SA-CORE-2014-004Project: Drupal core Version: 6.x, 7.xDate: 2014-August-06Security risk: 13/25 ( Moderately Critical) AC:None/A:None/CI:None/II:None/E:Proof/TD:100Exploitable from: RemoteVulnerability: Denial of serviceDescriptionDrupal 6 and Drupal 7 include an XML-RPC endpoint which is publicly available (xmlrpc.php). The PHP XML parser used by this XML-RPC endpoint is vulnerable to an XML entity expansion attack and other related XML payload attacks which can cause CPU

More info:

https://www.drupal.org/SA-CORE-2014-004