WordPress Core <= 2.8.4 - Denial of Service
2009-10-20 00:00
AnonymousStrategic Overview
StatusPatched in 2.8.5
Affected CoreWordPress 2.8
Affected Version
<= 2.8.4CVSS6.5Medium
CVE
CVE-2009-3622Vulnerability Overview
Algorithmic complexity vulnerability in wp-trackback.php in WordPress before 2.8.5 allows remote attackers to cause a denial of service (CPU consumption and server hang) via a long title parameter in conjunction with a charset parameter composed of many comma-separated "UTF-8" substrings, related to the mb_convert_encoding function in PHP.
Technical Analysis
REMEDIATION: Update to version 2.8.5, or a newer patched version --- IDENTIFIER: CWE-400 (Uncontrolled Resource Consumption) The product does not properly control the allocation and maintenance of a limited resource.
External References
Vulnerability data © Defiant, Inc., provided under the Wordfence Intelligence T&C