CVE-2012-1588

low
Published 2012-10-01 · Modified 2026-04-29
CVSS v3
CVSS v2
3.5
VIR risk
3.5

Description

Algorithmic complexity vulnerability in the _filter_url function in the text filtering system (modules/filter/filter.module) in Drupal 7.x before 7.14 allows remote authenticated users with certain roles to cause a denial of service (CPU consumption) via a long email address.

Predictions

Exploit likelihood
20%
Patch ETA

Heuristic predictions, AS-IS, for prioritization only.

Mitigations

vendor Authored 2026-05-27

Vendor advisory: secalert@redhat.com — http://drupal.org/node/1558468

vendor Authored 2026-05-27

Vendor advisory: secalert@redhat.com — http://drupal.org/node/1557938

vendor Authored 2026-05-27

Vendor advisory: secalert@redhat.com — http://drupal.org/drupal-7.14

Application impact

VendorProductVersionsFixed
drupaldrupal7.0
drupaldrupal7.1
drupaldrupal7.2
drupaldrupal7.3
drupaldrupal7.4
drupaldrupal7.5
drupaldrupal7.6
drupaldrupal7.7
drupaldrupal7.8
drupaldrupal7.9
drupaldrupal7.10
drupaldrupal7.11
drupaldrupal7.12
drupaldrupal7.13
drupaldrupal7.x-dev

References

CWEs

CWE-399

Verify integrity in audit chain (admin only). AS-IS.