CVE-2014-9016: Debian Linux
Medium severity, CVSS 5.0. EPSS: 82.2% chance of exploitation in the next 30 days.
The password hashing API in Drupal 7.x before 7.34 and the Secure Password Hashes (aka phpass) module 6.x-2.x before 6.x-2.1 for Drupal allows remote attackers to cause a denial of service (CPU and memory consumption) via a crafted request.
Affected products
- Debian Debian Linux: version 7.0 only
- Drupal Drupal: from 7.0, before 7.34 (fixed in 7.34)
- Secure Password Hashes Project Secure Passwords Hashes: from 6.x-2.0, before 6.x-2.1 (fixed in 6.x-2.1)
Published 2014-11-24. Last modified 2026-06-17.