CVE-2014-9034

wp-includes/class-phpass.php in WordPress before 3.7.5, 3.8.x before 3.8.5, 3.9.x before 3.9.3, and 4.x before 4.0.1 allows remote attackers to cause a denial of service (CPU consumption) via a long password that is improperly handled during hashing, a similar issue to CVE-2014-9016.
Configurations

Configuration 1 (hide)

OR cpe:2.3:a:wordpress:wordpress:*:*:*:*:*:*:*:*
cpe:2.3:a:wordpress:wordpress:3.8:*:*:*:*:*:*:*
cpe:2.3:a:wordpress:wordpress:3.8.1:*:*:*:*:*:*:*
cpe:2.3:a:wordpress:wordpress:3.8.2:*:*:*:*:*:*:*
cpe:2.3:a:wordpress:wordpress:3.8.3:*:*:*:*:*:*:*
cpe:2.3:a:wordpress:wordpress:3.8.4:*:*:*:*:*:*:*
cpe:2.3:a:wordpress:wordpress:3.9:*:*:*:*:*:*:*
cpe:2.3:a:wordpress:wordpress:3.9.1:*:*:*:*:*:*:*
cpe:2.3:a:wordpress:wordpress:3.9.2:*:*:*:*:*:*:*
cpe:2.3:a:wordpress:wordpress:4.0:*:*:*:*:*:*:*

History

No history.

Information

Published : 2014-11-25 23:59

Updated : 2023-12-10 11:31


NVD link : CVE-2014-9034

Mitre link : CVE-2014-9034

CVE.ORG link : CVE-2014-9034


JSON object : View

Products Affected

wordpress

  • wordpress
CWE
CWE-19

Data Processing Errors