Protect yourself against future threats.
-----BEGIN PGP SIGNED MESSAGE----- Hash: SHA1 =========================================================================== AUSCERT External Security Bulletin Redistribution ESB-2013.0238 A vulnerability has been identified in Drupal core 21 February 2013 =========================================================================== AusCERT Security Bulletin Summary --------------------------------- Product: Drupal Publisher: Drupal Operating System: UNIX variants (UNIX, Linux, OSX) Windows Impact/Access: Denial of Service -- Remote/Unauthenticated Resolution: Patch/Upgrade Original Bulletin: http://drupal.org/SA-CORE-2013-002 - --------------------------BEGIN INCLUDED TEXT-------------------- * Advisory ID: DRUPAL-SA-CORE-2013-002 * Project: Drupal core [1] * Version: 7.x * Date: 2013-February-20 * Security risk: Critical [2] * Exploitable from: Remote * Vulnerability: Denial of service - -------- DESCRIPTION --------------------------------------------------------- Drupal core's Image module allows for the on-demand generation of image derivatives. This capability can be abused by requesting a large number of new derivatives which can fill up the server disk space, and which can cause a very high CPU load. Either of these effects may lead to the site becoming unavailable or unresponsive. Please see the Drupal 7.20 release notes [3] for important notes about the changes which were made to fix this issue, since some sites will require extra testing and care when deploying this Drupal core release. - -------- CVE IDENTIFIER(S) ISSUED -------------------------------------------- * /A CVE identifier [4] will be requested, and added upon issuance, in accordance with Drupal Security Team processes./ - -------- VERSIONS AFFECTED --------------------------------------------------- * Drupal core 7.x versions prior to 7.20. - -------- SOLUTION ------------------------------------------------------------ Install the latest version: * If you use Drupal 7.x, upgrade to Drupal core 7.20 [5]. Also see the Drupal core [6] project page. - -------- REPORTED BY --------------------------------------------------------- * Bèr Kessels [7] * aBrookland [8] * Chad Fennell [9] - -------- FIXED BY ------------------------------------------------------------ * Damien Tournoud [10] of the Drupal Security Team * Peter Wolanin [11] of the Drupal Security Team * David Rothstein [12] of the Drupal Security Team * Heine Deelstra [13] of the Drupal Security Team * Bèr Kessels [14] - -------- COORDINATED BY ------------------------------------------------------ * David Rothstein [15] of the Drupal Security Team * Stéphane Corlosquet [16] of the Drupal Security Team * Peter Wolanin [17] of the Drupal Security Team * Greg Knaddison [18] of the Drupal Security Team - -------- CONTACT AND MORE INFORMATION ---------------------------------------- The Drupal security team can be reached at security at drupal.org or via the contact form at http://drupal.org/contact [19]. Learn more about the Drupal Security team and their policies [20], writing secure code for Drupal [21], and securing your site [22]. [1] http://drupal.org/project/drupal [2] http://drupal.org/security-team/risk-levels [3] http://drupal.org/drupal-7.20-release-notes [4] http://cve.mitre.org/ [5] http://drupal.org/drupal-7.20-release-notes [6] http://drupal.org/project/drupal [7] http://drupal.org/user/2663 [8] http://drupal.org/user/2274988 [9] http://drupal.org/user/10297 [10] http://drupal.org/user/22211 [11] http://drupal.org/user/49851 [12] http://drupal.org/user/124982 [13] http://drupal.org/user/17943 [14] http://drupal.org/user/2663 [15] http://drupal.org/user/124982 [16] http://drupal.org/user/52142 [17] http://drupal.org/user/49851 [18] http://drupal.org/user/36762 [19] http://drupal.org/contact [20] http://drupal.org/security-team [21] http://drupal.org/writing-secure-code [22] http://drupal.org/security/secure-configuration - --------------------------END INCLUDED TEXT-------------------- You have received this e-mail bulletin as a result of your organisation's registration with AusCERT. The mailing list you are subscribed to is maintained within your organisation, so if you do not wish to continue receiving these bulletins you should contact your local IT manager. If you do not know who that is, please send an email to auscert@auscert.org.au and we will forward your request to the appropriate person. NOTE: Third Party Rights This security bulletin is provided as a service to AusCERT's members. As AusCERT did not write the document quoted above, AusCERT has had no control over its content. The decision to follow or act on information or advice contained in this security bulletin is the responsibility of each user or organisation, and should be considered in accordance with your organisation's site policies and procedures. AusCERT takes no responsibility for consequences which may arise from following or acting on information or advice contained in this security bulletin. NOTE: This is only the original release of the security bulletin. It may not be updated when updates to the original are made. If downloading at a later date, it is recommended that the bulletin is retrieved directly from the author's website to ensure that the information is still current. Contact information for the authors of the original document is included in the Security Bulletin above. If you have any questions or need further information, please contact them directly. Previous advisories and external security bulletins can be retrieved from: http://www.auscert.org.au/render.html?cid=1980 =========================================================================== Australian Computer Emergency Response Team The University of Queensland Brisbane Qld 4072 Internet Email: auscert@auscert.org.au Facsimile: (07) 3365 7031 Telephone: (07) 3365 4417 (International: +61 7 3365 4417) AusCERT personnel answer during Queensland business hours which are GMT+10:00 (AEST). On call after hours for member emergencies only. =========================================================================== -----BEGIN PGP SIGNATURE----- Comment: http://www.auscert.org.au/render.html?it=1967 iQIVAwUBUSXFBO4yVqjM2NGpAQJs2RAAk+HBTnptFurUnBZQF19gWm149tj09t+f 81HiIGpdcexsbcGIzodlZwoId5K8icGwsgeuP0ENRTa+WTHgSpERoZFYh7BBBUNP cyo1fKhxzl6VmFLmEvqDDLTBx+dHIPfSqNNbTz+cJylzbOf8u3iSN2976dbNwzkh PsF7Q0j1yBJ0yG6ecPBvxncCKdxNCi354fBOw0So7RYHC1o+/tBGgZLA3idWBIJw 9eCop/i34dXTXP7jpJDi7Wuio8htEA6f4N/ECHYcm4siqAdLmHtIrmuYtRld1H6R LIIJvk7rFnRibhFP3Z9ews5/FWf/+HIF97B39Y7nITy6h0GVSoSClyTnbmc5mFdg p13pTdKHwjd5ngYJMvSDXMjjj7UqFcqyosyFw042GqTCzKaA04LngW8+y1UwzmIf rYDrHy2seRfrFoJzck33ZXVbUzaD1d30hE0WRoVw3Q58GzXbq3bjrmy+zFg4Afm+ JG83GUPTFMpTbCrDV5TU+Ze01Xcm/AJB4UnyKTmp64GiKHWsXIjyKQ5I4H/SzGzj XMVrc2RcgGBRBHhLRD0UihjvB4Y2pH5BBe2cib/qssXwXoAC4G5txlcnziKOWB2m lF1ZH+8Kr87gsdu8D2HzoFuSiRrfsPLvbmHgv4rdlmOk1yQ9ZAsYySo0BfkUxbt5 EHzT45snQZc= =yUSY -----END PGP SIGNATURE-----