CVE-2009-3622
EPSS 8.3%
Description
Algorithmic complexity vulnerability in wp-trackback.php in WordPress before 2.8.5 allows remote attackers to cause a denial of service (CPU consumption and server hang) via a long title parameter in conjunction with a charset parameter composed of many comma-separated "UTF-8" substrings, related to the mb_convert_encoding function in PHP.
How to fix CVE-2009-3622
To remediate CVE-2009-3622, upgrade the affected package to a fixed version below.
- Debian/wordpress—upgrade to 2.8.5-1 or later
Is CVE-2009-3622 being exploited?
Moderate — EPSS is 8.3%. Track this CVE but it's not at the top of the prioritisation list.
Affected packages (1)
- from 0, < 2.8.5-1