CVE Vulnerabilities

CVE-2014-9034

Published: Nov 25, 2014 | Modified: Apr 04, 2016
CVSS 3.x
N/A
Source:
NVD
CVSS 2.x
5 MEDIUM
AV:N/AC:L/Au:N/C:N/I:N/A:P
RedHat/V2
RedHat/V3
Ubuntu
MEDIUM

wp-includes/class-phpass.php in WordPress before 3.7.5, 3.8.x before 3.8.5, 3.9.x before 3.9.3, and 4.x before 4.0.1 allows remote attackers to cause a denial of service (CPU consumption) via a long password that is improperly handled during hashing, a similar issue to CVE-2014-9016.

Affected Software

Name Vendor Start Version End Version
Wordpress Wordpress * 3.7.4 (including)
Wordpress Wordpress 3.8 (including) 3.8 (including)
Wordpress Wordpress 3.8.1 (including) 3.8.1 (including)
Wordpress Wordpress 3.8.2 (including) 3.8.2 (including)
Wordpress Wordpress 3.8.3 (including) 3.8.3 (including)
Wordpress Wordpress 3.8.4 (including) 3.8.4 (including)
Wordpress Wordpress 3.9 (including) 3.9 (including)
Wordpress Wordpress 3.9.1 (including) 3.9.1 (including)
Wordpress Wordpress 3.9.2 (including) 3.9.2 (including)
Wordpress Wordpress 4.0 (including) 4.0 (including)
Wordpress Ubuntu lucid *
Wordpress Ubuntu precise *
Wordpress Ubuntu trusty *
Wordpress Ubuntu upstream *
Wordpress Ubuntu utopic *

References