CVE Vulnerabilities

CVE-2014-9034

Published: Nov 25, 2014 | Modified: Apr 04, 2016
CVSS 3.x
N/A
Source:
NVD
CVSS 2.x
5 MEDIUM
AV:N/AC:L/Au:N/C:N/I:N/A:P
RedHat/V2
RedHat/V3
Ubuntu

wp-includes/class-phpass.php in WordPress before 3.7.5, 3.8.x before 3.8.5, 3.9.x before 3.9.3, and 4.x before 4.0.1 allows remote attackers to cause a denial of service (CPU consumption) via a long password that is improperly handled during hashing, a similar issue to CVE-2014-9016.

Affected Software

Name Vendor Start Version End Version
Wordpress Wordpress * 3.7.4 (including)
Wordpress Wordpress 3.8 (including) 3.8 (including)
Wordpress Wordpress 3.8.1 (including) 3.8.1 (including)
Wordpress Wordpress 3.8.2 (including) 3.8.2 (including)
Wordpress Wordpress 3.8.3 (including) 3.8.3 (including)
Wordpress Wordpress 3.8.4 (including) 3.8.4 (including)
Wordpress Wordpress 3.9 (including) 3.9 (including)
Wordpress Wordpress 3.9.1 (including) 3.9.1 (including)
Wordpress Wordpress 3.9.2 (including) 3.9.2 (including)
Wordpress Wordpress 4.0 (including) 4.0 (including)

References