Description
The Adaptive Image module provides responsive image delivery by generating image style derivatives scaled to the client's detected screen resolution.
The module's delivery callback (`adaptive_image_style_deliver`) does not check whether the source image exists before proceeding to lock acquisition and derivative generation. When a request arrives for a non-existent source file, the module acquires a database lock, invokes the image toolkit (potentially spawning an ImageMagick subprocess), writes a watchdog error entry, and returns a 500 Internal Server Error rather than a 404.
This vulnerability is mitigated by the fact that the image delivery endpoint is only reachable on sites that have the Adaptive Image module installed and have at least one image style configured with the adaptive image effect; the module's internal lock mechanism also causes repeated requests for the same non-existent URI to return 503 rather than re-entering the generation path.
Solution
Install the latest version.
If you use the Adaptive Image module for Drupal 7, upgrade to Adaptive Image 7.x-1.7:
Reported by
Fixed by
- Tag1 D7ES
Coordinated by
- Tag1 D7ES