CVE-2013-4599
Published Jun 9, 2014
Last updated 10 years ago
Overview
- Description
- The Misery module 6.x-2.x before 6.x-2.5 and 7.x-2.x before 7.x-2.2 for Drupal, when the "delay misery" configuration is set to a high value, allows remote attackers to cause a denial of service (process consumption) via multiple requests.
- Source
- secalert@redhat.com
- NVD status
- Analyzed
Risk scores
CVSS 2.0
- Type
- Primary
- Base score
- 4.3
- Impact score
- 2.9
- Exploitability score
- 8.6
- Vector string
- AV:N/AC:M/Au:N/C:N/I:N/A:P
Weaknesses
- nvd@nist.gov
- CWE-399
Social media
- Hype score
- Not currently trending
Configurations
[ { "nodes": [ { "negate": false, "cpeMatch": [ { "criteria": "cpe:2.3:a:misery_project:misery:6.x-2.0:-:-:*:-:drupal:*:*", "vulnerable": true, "matchCriteriaId": "1060C5B7-025B-432C-BF6B-2B0C25A74D87" }, { "criteria": "cpe:2.3:a:misery_project:misery:6.x-2.1:-:-:*:-:drupal:*:*", "vulnerable": true, "matchCriteriaId": "F5939A66-16DB-406B-9AD9-A48E6DA959EC" }, { "criteria": "cpe:2.3:a:misery_project:misery:6.x-2.2:-:-:*:-:drupal:*:*", "vulnerable": true, "matchCriteriaId": "33DB7FE2-8788-4E0A-8F3F-931512BFED58" }, { "criteria": "cpe:2.3:a:misery_project:misery:6.x-2.3:-:-:*:-:drupal:*:*", "vulnerable": true, "matchCriteriaId": "4632A5C6-B375-40BE-8BE6-B36456D35F58" }, { "criteria": "cpe:2.3:a:misery_project:misery:6.x-2.4:-:-:*:-:drupal:*:*", "vulnerable": true, "matchCriteriaId": "A990C479-179D-428E-8B52-E080D0BDE514" }, { "criteria": "cpe:2.3:a:misery_project:misery:7.x-2.0:-:-:*:-:drupal:*:*", "vulnerable": true, "matchCriteriaId": "116313ED-5DFF-49F6-A533-A6D75F35CFD8" }, { "criteria": "cpe:2.3:a:misery_project:misery:7.x-2.1:-:-:*:-:drupal:*:*", "vulnerable": true, "matchCriteriaId": "1A99CA68-2593-4E08-89C7-6177647EFE39" } ], "operator": "OR" } ] } ]