WordPress Core <= 2.8.4 - Denial of Service

2009-10-20 00:00
Anonymous

Strategic Overview

Status
Patched in 2.8.5
Affected CoreWordPress 2.8
Affected Version<= 2.8.4
CVSS6.5Medium
CVECVE-2009-3622
View all WordPress 2.8 vulnerabilities

Vulnerability Overview

Algorithmic complexity vulnerability in wp-trackback.php in WordPress before 2.8.5 allows remote attackers to cause a denial of service (CPU consumption and server hang) via a long title parameter in conjunction with a charset parameter composed of many comma-separated "UTF-8" substrings, related to the mb_convert_encoding function in PHP.

Technical Analysis

REMEDIATION: Update to version 2.8.5, or a newer patched version --- IDENTIFIER: CWE-400 (Uncontrolled Resource Consumption) The product does not properly control the allocation and maintenance of a limited resource.

External References

Vulnerability data © Defiant, Inc., provided under the Wordfence Intelligence T&C