WordPress Core < 3.1.1 - Denial of Service

2011-04-05 00:00
Anonymous

Strategic Overview

Status
Patched in 3.1.1
Affected CoreWordPress 3.1
Affected Version< 3.1.1
CVSS7.5High
CVECVE-2011-4957
View all WordPress 3.1 vulnerabilities

Vulnerability Overview

The make_clickable function in wp-includes/formatting.php in WordPress before 3.1.1 does not properly check URLs before passing them to the PCRE library, which allows remote attackers to cause a denial of service (crash) via a comment with a crafted URL that triggers many recursive calls.

Technical Analysis

REMEDIATION: Update to version 3.1.1, or a newer patched version --- IDENTIFIER: CWE-400 (Uncontrolled Resource Consumption) The product does not properly control the allocation and maintenance of a limited resource.

External References

Vulnerability data © Defiant, Inc., provided under the Wordfence Intelligence T&C