Bug 530056 (CVE-2009-3622)

Summary: CVE-2009-3622 WordPress: Resource exhaustion (DoS)
Product: [Other] Security Response Reporter: Jan Lieskovsky <jlieskov>
Component: vulnerabilityAssignee: Red Hat Product Security <security-response-team>
Status: CLOSED ERRATA QA Contact:
Severity: low Docs Contact:
Priority: low    
Version: unspecifiedKeywords: Security
Target Milestone: ---   
Target Release: ---   
Hardware: All   
OS: Linux   
URL: http://wordpress.org/development/2009/10/wordpress-2-8-5-hardening-release/
Whiteboard:
Fixed In Version: Doc Type: Bug Fix
Doc Text:
Story Points: ---
Clone Of: Environment:
Last Closed: 2012-09-14 22:10:31 UTC Type: ---
Regression: --- Mount Type: ---
Documentation: --- CRM:
Verified Versions: Category: ---
oVirt Team: --- RHEL 7.3 requirements from Atomic Host:
Cloudforms Team: --- Target Upstream Version:
Embargoed:

Description Jan Lieskovsky 2009-10-21 11:52:43 UTC
A denial of service (resource exhaustion) flaw was found in the way
WordPress used to handle HTTP headers, contained in the "trackback"
message, sent to WordPress. A local, unprivileged user could
sent a specially-crafted trackback message to running instance
of WordPress, leading to its crash.

References:
----------
http://wordpress.org/development/2009/10/wordpress-2-8-5-hardening-release/
http://seclists.org/fulldisclosure/2009/Oct/263

PoC:
----
http://codes.zerial.org/php/wp-trackbacks_dos.phps

CVE was requested here:
-----------------------
http://www.openwall.com/lists/oss-security/2009/10/21/2

Comment 1 Jan Lieskovsky 2009-10-21 11:57:34 UTC
This issue affects current versions of the wordpress package, as shipped
with Fedora releases of 10 and 11 and within Extra Packages for Enterprise
Linux 5 (EPEL-5) project (wordpress-2.8.4-1.fc10, wordpress-2.8.4-1.fc11,
wordpress-2.8.4-1.el5).

This issue affects the version of the wordpress package, as scheduled
to be included in Fedora release of 12 (wordpress-2.8.4-1.fc12).

Please fix.

This issue does NOT affect the version of wordpress package, as shipped
within Rawhide (wordpress-2.8.5-1.fc13 already contains upstream 2.8.5
hardened version).

Comment 2 Fedora Update System 2009-10-21 14:30:30 UTC
wordpress-2.8.5-1.fc12 has been submitted as an update for Fedora 12.
http://admin.fedoraproject.org/updates/wordpress-2.8.5-1.fc12

Comment 3 Fedora Update System 2009-10-21 14:31:33 UTC
wordpress-2.8.5-1.fc11 has been submitted as an update for Fedora 11.
http://admin.fedoraproject.org/updates/wordpress-2.8.5-1.fc11

Comment 4 Fedora Update System 2009-10-21 14:32:21 UTC
wordpress-2.8.5-1.fc10 has been submitted as an update for Fedora 10.
http://admin.fedoraproject.org/updates/wordpress-2.8.5-1.fc10

Comment 5 Fedora Update System 2009-10-21 14:32:55 UTC
wordpress-2.8.5-1.el5 has been submitted as an update for Fedora EPEL 5.
http://admin.fedoraproject.org/updates/wordpress-2.8.5-1.el5

Comment 6 Fedora Update System 2009-10-23 23:21:59 UTC
wordpress-2.8.5-1.el5 has been pushed to the Fedora EPEL 5 stable repository.  If problems still persist, please make note of it in this bug report.

Comment 7 Fedora Update System 2009-10-27 06:54:38 UTC
wordpress-2.8.5-1.fc11 has been pushed to the Fedora 11 stable repository.  If problems still persist, please make note of it in this bug report.

Comment 8 Fedora Update System 2009-10-27 06:55:26 UTC
wordpress-2.8.5-1.fc10 has been pushed to the Fedora 10 stable repository.  If problems still persist, please make note of it in this bug report.

Comment 9 Fedora Update System 2009-11-06 21:59:08 UTC
wordpress-mu-2.8.5.2-1.el5 has been submitted as an update for Fedora EPEL 5.
http://admin.fedoraproject.org/updates/wordpress-mu-2.8.5.2-1.el5

Comment 10 Fedora Update System 2009-11-06 22:19:27 UTC
wordpress-mu-2.8.5.2-1.fc11 has been submitted as an update for Fedora 11.
http://admin.fedoraproject.org/updates/wordpress-mu-2.8.5.2-1.fc11

Comment 11 Fedora Update System 2009-11-06 22:20:20 UTC
wordpress-mu-2.8.5.2-1.fc10 has been submitted as an update for Fedora 10.
http://admin.fedoraproject.org/updates/wordpress-mu-2.8.5.2-1.fc10

Comment 12 Fedora Update System 2009-11-10 03:22:36 UTC
wordpress-mu-2.8.5.2-1.el5 has been pushed to the Fedora EPEL 5 stable repository.  If problems still persist, please make note of it in this bug report.

Comment 13 Fedora Update System 2009-11-10 17:54:02 UTC
wordpress-mu-2.8.5.2-1.fc11 has been pushed to the Fedora 11 stable repository.  If problems still persist, please make note of it in this bug report.

Comment 14 Fedora Update System 2009-11-10 17:56:59 UTC
wordpress-mu-2.8.5.2-1.fc10 has been pushed to the Fedora 10 stable repository.  If problems still persist, please make note of it in this bug report.