Vulnerability Bulletins

SA-CORE-2014-003 - Drupal core - Multiple vulnerabilities

   
Affected software Drupal
 
Advisory ID: DRUPAL-SA-CORE-2014-003Project: Drupal coreVersion: 6.x, 7.xDate: 2014-July-16Security risk: CriticalExploitable from: RemoteVulnerability: Multiple vulnerabilitiesDescriptionMultiple vulnerabilities were fixed in the supported Drupal core versions 6 and 7.Denial of service with malicious HTTP Host header (Base system - Drupal 6 and 7 - Critical)Drupal cores multisite feature dynamically determines which configuration file to use based on the HTTP Host header.The HTTP Host header

More info:

https://www.drupal.org/SA-CORE-2014-003