The Misery module 6.x-2.x before 6.x-2.5 and 7.x-2.x before 7.x-2.2 for Drupal, when the "delay misery" configuration is set to a high value, allows remote attackers to cause a denial of service (process consumption) via multiple requests.
Weaknesses in this category are related to improper management of system resources.
Link | Tags |
---|---|
https://drupal.org/node/2134413 | patch |
https://drupal.org/node/2135273 | vendor advisory |
http://www.securityfocus.com/bid/63705 | vdb entry |
https://drupal.org/node/2134409 | patch |
http://seclists.org/oss-sec/2013/q4/317 | mailing list |