Back to search
CVE-2009-3622
Published: Oct 23, 2009
Modified: Aug 7, 2024
PUBLISHED
Description
Algorithmic complexity vulnerability in wp-trackback.php in WordPress before 2.8.5 allows remote attackers to cause a denial of service (CPU consumption and server hang) via a long title parameter in conjunction with a charset parameter composed of many comma-separated "UTF-8" substrings, related to the mb_convert_encoding function in PHP.
| Vendor | Product | Versions |
|---|---|---|
n/a | n/a | affected n/a |
References
20091019 [Wordpress] Resource Exhaustion (Denial of Service)
mailing-list
x_refsource_FULLDISC
wordpress-wptrackback-dos(53884)
vdb-entry
x_refsource_XF
[oss-security] 20091021 Re: CVE request: Wordpress Trackback DoS
mailing-list
x_refsource_MLIST
http://codes.zerial.org/php/wp-trackbacks_dos.phps
x_refsource_MISC
37088
third-party-advisory
x_refsource_SECUNIA
59077
vdb-entry
x_refsource_OSVDB
ADV-2009-2986
vdb-entry
x_refsource_VUPEN
https://bugzilla.redhat.com/show_bug.cgi?id=530056
x_refsource_CONFIRM
[oss-security] 20091021 CVE request: Wordpress Trackback DoS
mailing-list
x_refsource_MLIST
1023072
vdb-entry
x_refsource_SECTRACK
http://wordpress.org/development/2009/10/wordpress-2-8-5-hardening-release/
x_refsource_CONFIRM
Security Training
Train your team to recognize and prevent security threats with our comprehensive security awareness program.
Start TrainingVulnerability Scanning
Discover vulnerabilities in your applications and infrastructure before attackers do.
Scan Now