Drupal.Core.xmlrpc.php.Internal.Entity.Expansion.DoS

description-logoDescription

This indicates an attack attempt to exploit A Denial-Of-Service vulnerability in Drupal Core.
The vulnerability is due to an input validation error when the affected application parses a XML-RPC packet. A remote attacker can exploit this to cause a denial of service condition in the affected application.

affected-products-logoAffected Products

Drupal Drupal 6.x prior to 6.33
Drupal Drupal 7.x prior to 7.31

Impact logoImpact

Denial of Service: Remote attackers can crash vulnerable systems.

recomended-action-logoRecommended Actions

Apply the latest update from the vendor
https://www.drupal.org/SA-CORE-2014-004

Telemetry logoTelemetry

Coverage

IPS (Regular DB)
IPS (Extended DB)