Date
Severity
Less Critical
Vulnerability
Denial of Service
Affected versions
<7.x-1.5

Description

The Adaptive Image module provides responsive image delivery by generating image style derivatives scaled to the client's detected screen resolution.

The module's delivery callback (`adaptive_image_style_deliver`) does not check whether the source image exists before proceeding to lock acquisition and derivative generation. When a request arrives for a non-existent source file, the module acquires a database lock, invokes the image toolkit (potentially spawning an ImageMagick subprocess), writes a watchdog error entry, and returns a 500 Internal Server Error rather than a 404.

This vulnerability is mitigated by the fact that the image delivery endpoint is only reachable on sites that have the Adaptive Image module installed and have at least one image style configured with the adaptive image effect; the module's internal lock mechanism also causes repeated requests for the same non-existent URI to return 503 rather than re-entering the generation path.

Solution

Install the latest version.

If you use the Adaptive Image module for Drupal 7, upgrade to Adaptive Image 7.x-1.7:


Reported by

Fixed by

  • Tag1 D7ES

Coordinated by

  • Tag1 D7ES