The RESTful Web Services (RESTWS) module 7.x-1.x before 7.x-1.3 and 7.x-2.x before 7.x-2.0-alpha5 for Drupal, when page caching is enabled and anonymous users are assigned RESTWS permissions, allows remote attackers to cause a denial of service via a GET request with an HTTP Accept header set to a non-HTML type, which can "interfere with Drupal's page cache."
The product receives input or data, but it does not validate or incorrectly validates that the input has the properties that are required to process the data safely and correctly.
Link | Tags |
---|---|
http://www.osvdb.org/92259 | vdb entry |
https://drupal.org/node/1966758 | patch vendor advisory |
https://drupal.org/node/1966752 | |
https://drupal.org/node/1966780 | patch vendor advisory |
http://www.openwall.com/lists/oss-security/2013/04/12/1 | mailing list |