Vulnerability Bulletins

SA-CORE-2012-002 - Drupal core multiple vulnerabilities

   
Affected software Drupal
 
Advisory ID: DRUPAL-SA-CORE-2012-002Project: Drupal coreVersion: 7.xDate: 2012-May-2Security risk: CriticalExploitable from: RemoteVulnerability: Denial of Service, Access bypass, Unvalidated form redirectDescriptionDenial of ServiceCVE: CVE-2012-1588Drupal cores text filtering system provides several features including removing inappropriate HTML tags and automatically linking content that appears to be a link. A pattern in Drupals text matching was found to be inefficient with certain

More info:

https://www.drupal.org/SA-CORE-2012-002