WordPress before 2.0.5 does not properly store a profile containing a string representation of a serialized object, which allows remote authenticated users to cause a denial of service (application crash) via a string that represents a (1) malformed or (2) large serialized object, because the object triggers automatic unserialization for display.
Name | Vendor | Start Version | End Version |
---|---|---|---|
Wordpress | Wordpress | * | 2.0.5 (including) |
Wordpress | Ubuntu | dapper | * |
Wordpress | Ubuntu | edgy | * |
Wordpress | Ubuntu | upstream | * |