Bug 530056 - (CVE-2009-3622) CVE-2009-3622 WordPress: Resource exhaustion (DoS)
CVE-2009-3622 WordPress: Resource exhaustion (DoS)
Status: CLOSED ERRATA
Product: Security Response
Classification: Other
Component: vulnerability (Show other bugs)
unspecified
All Linux
low Severity low
: ---
: ---
Assigned To: Red Hat Product Security
http://wordpress.org/development/2009...
impact=low,source=osssecurity,reporte...
: Security
Depends On:
Blocks:
  Show dependency treegraph
 
Reported: 2009-10-21 07:52 EDT by Jan Lieskovsky
Modified: 2012-09-14 18:10 EDT (History)
0 users

See Also:
Fixed In Version:
Doc Type: Bug Fix
Doc Text:
Story Points: ---
Clone Of:
Environment:
Last Closed: 2012-09-14 18:10:31 EDT
Type: ---
Regression: ---
Mount Type: ---
Documentation: ---
CRM:
Verified Versions:
Category: ---
oVirt Team: ---
RHEL 7.3 requirements from Atomic Host:


Attachments (Terms of Use)

  None (edit)
Description Jan Lieskovsky 2009-10-21 07:52:43 EDT
A denial of service (resource exhaustion) flaw was found in the way
WordPress used to handle HTTP headers, contained in the "trackback"
message, sent to WordPress. A local, unprivileged user could
sent a specially-crafted trackback message to running instance
of WordPress, leading to its crash.

References:
----------
http://wordpress.org/development/2009/10/wordpress-2-8-5-hardening-release/
http://seclists.org/fulldisclosure/2009/Oct/263

PoC:
----
http://codes.zerial.org/php/wp-trackbacks_dos.phps

CVE was requested here:
-----------------------
http://www.openwall.com/lists/oss-security/2009/10/21/2
Comment 1 Jan Lieskovsky 2009-10-21 07:57:34 EDT
This issue affects current versions of the wordpress package, as shipped
with Fedora releases of 10 and 11 and within Extra Packages for Enterprise
Linux 5 (EPEL-5) project (wordpress-2.8.4-1.fc10, wordpress-2.8.4-1.fc11,
wordpress-2.8.4-1.el5).

This issue affects the version of the wordpress package, as scheduled
to be included in Fedora release of 12 (wordpress-2.8.4-1.fc12).

Please fix.

This issue does NOT affect the version of wordpress package, as shipped
within Rawhide (wordpress-2.8.5-1.fc13 already contains upstream 2.8.5
hardened version).
Comment 2 Fedora Update System 2009-10-21 10:30:30 EDT
wordpress-2.8.5-1.fc12 has been submitted as an update for Fedora 12.
http://admin.fedoraproject.org/updates/wordpress-2.8.5-1.fc12
Comment 3 Fedora Update System 2009-10-21 10:31:33 EDT
wordpress-2.8.5-1.fc11 has been submitted as an update for Fedora 11.
http://admin.fedoraproject.org/updates/wordpress-2.8.5-1.fc11
Comment 4 Fedora Update System 2009-10-21 10:32:21 EDT
wordpress-2.8.5-1.fc10 has been submitted as an update for Fedora 10.
http://admin.fedoraproject.org/updates/wordpress-2.8.5-1.fc10
Comment 5 Fedora Update System 2009-10-21 10:32:55 EDT
wordpress-2.8.5-1.el5 has been submitted as an update for Fedora EPEL 5.
http://admin.fedoraproject.org/updates/wordpress-2.8.5-1.el5
Comment 6 Fedora Update System 2009-10-23 19:21:59 EDT
wordpress-2.8.5-1.el5 has been pushed to the Fedora EPEL 5 stable repository.  If problems still persist, please make note of it in this bug report.
Comment 7 Fedora Update System 2009-10-27 02:54:38 EDT
wordpress-2.8.5-1.fc11 has been pushed to the Fedora 11 stable repository.  If problems still persist, please make note of it in this bug report.
Comment 8 Fedora Update System 2009-10-27 02:55:26 EDT
wordpress-2.8.5-1.fc10 has been pushed to the Fedora 10 stable repository.  If problems still persist, please make note of it in this bug report.
Comment 9 Fedora Update System 2009-11-06 16:59:08 EST
wordpress-mu-2.8.5.2-1.el5 has been submitted as an update for Fedora EPEL 5.
http://admin.fedoraproject.org/updates/wordpress-mu-2.8.5.2-1.el5
Comment 10 Fedora Update System 2009-11-06 17:19:27 EST
wordpress-mu-2.8.5.2-1.fc11 has been submitted as an update for Fedora 11.
http://admin.fedoraproject.org/updates/wordpress-mu-2.8.5.2-1.fc11
Comment 11 Fedora Update System 2009-11-06 17:20:20 EST
wordpress-mu-2.8.5.2-1.fc10 has been submitted as an update for Fedora 10.
http://admin.fedoraproject.org/updates/wordpress-mu-2.8.5.2-1.fc10
Comment 12 Fedora Update System 2009-11-09 22:22:36 EST
wordpress-mu-2.8.5.2-1.el5 has been pushed to the Fedora EPEL 5 stable repository.  If problems still persist, please make note of it in this bug report.
Comment 13 Fedora Update System 2009-11-10 12:54:02 EST
wordpress-mu-2.8.5.2-1.fc11 has been pushed to the Fedora 11 stable repository.  If problems still persist, please make note of it in this bug report.
Comment 14 Fedora Update System 2009-11-10 12:56:59 EST
wordpress-mu-2.8.5.2-1.fc10 has been pushed to the Fedora 10 stable repository.  If problems still persist, please make note of it in this bug report.

Note You need to log in before you can comment on or make changes to this bug.