-----BEGIN PGP SIGNED MESSAGE----- Hash: SHA512 - ------------------------------------------------------------------------- Debian Security Advisory DSA-2999-1 security@debian.org http://www.debian.org/security/ Salvatore Bonaccorso August 09, 2014 http://www.debian.org/security/faq - ------------------------------------------------------------------------- Package : drupal7 CVE ID : not yet available A denial of service vulnerability was discovered in Drupal, a fully-featured content management framework. A remote attacker could exploit this flaw to cause CPU and memory exhaustion and the site's database to reach the maximum number of open connections, leading to the site becoming unavailable or unresponsive. More information can be found at https://www.drupal.org/SA-CORE-2014-004 For the stable distribution (wheezy), this problem has been fixed in version 7.14-2+deb7u6. For the testing distribution (jessie), this problem has been fixed in version 7.31-1. For the unstable distribution (sid), this problem has been fixed in version 7.31-1. We recommend that you upgrade your drupal7 packages. Further information about Debian Security Advisories, how to apply these updates to your system and frequently asked questions can be found at: https://www.debian.org/security/ Mailing list: debian-security-announce@lists.debian.org -----BEGIN PGP SIGNATURE----- Version: GnuPG v1 iQIcBAEBCgAGBQJT5ck1AAoJEAVMuPMTQ89EpPQP/0pEBJ5khncKFyCuTdiJRkf8 /ohLYfUwyjG4DEs4RMUB/qkw3nwt7hUtJ32If/EOTbPXEthRhZkW0ILDY97lByxe u3DYjvK49xub7kRESN81D//iKrRBaPFGSwDjr/4xtC3Zssz2i5/7EerBdKwGR+Df o+cVh1WxuK5Jm8PlOaKVeB06Ag/cGB+pKICWEIphbhQp0JF/YaI5prWuxoHqp+n2 2BM1D+PhVLWdB7dQBjEjgxdbBhDjGWI04S3fce4lI6hBwoDrlO5yREpwFpVLKjDZ pkzJMxGcm2XUycf6GVPBpQI5v2vJEG/RHyPXZv1CxNKCI82QYA7qEQW9fVPX7eAb Gy9nDeI01FySPX91V9d2ZH+7qzte+NuqfMOtf98YlXQAyguH1Jdg5DjhbKmZ2QaC 4B+vYpsfu3kkCdyaXcFtlJLoCuZro2mXkUoovZfXfXNdiVyJHS8N9k1p5jRql+2q /rtj2o9R0D11hOZkC68GP/lPvsIwNjIrUuB+TQc7MXOoDUyeLDOVxZfKzRIVjjUL U2KozDKtpx74EljL5K75YjIFeOKMJkViVnwpmWfCMppNa2r+TOqqsTjBWaduijIc LVb2jFIKgnIdmAWzo685b+sEHloDRedm5yL2LYSMekplnzIcqHLjpZdnjJ2wxnYa Q8VodfEAIOa6w/2F1szP =FoSv -----END PGP SIGNATURE-----