The Hotblocks module 6.x-1.x before 6.x-1.8 for Drupal allows remote authenticated users with the administer hotblocks permission to cause a denial of service (infinite loop and time out) via a block that references itself.
| Name | Vendor | Start Version | End Version |
|---|---|---|---|
| Hotblocks | Justin_dodge | 6.x-1.5 (including) | 6.x-1.5 (including) |
| Hotblocks | Justin_dodge | 6.x-1.6 (including) | 6.x-1.6 (including) |
| Hotblocks | Justin_dodge | 6.x-1.7 (including) | 6.x-1.7 (including) |
| Hotblocks | Justin_dodge | 6.x-1.x-dev (including) | 6.x-1.x-dev (including) |