CVE-2007-0539: High severity WordPress vulnerability
Published Jan 29, 2007
·Updated
The wpremotefopen function in WordPress before 2.1 allows remote attackers to cause a denial of service (bandwidth or thread consumption) via pingback service calls with a source URI that corresponds to a large file, which triggers a long download session without a timeout constraint.
Affected Software
1 affected component
WordPress<=2.0
Event History
Jan 29, 2007
CVE Published
05:28 PM
CVE Published
via MITRE·10:00 PM
Data Sourced
via MITRE·10:00 PM
Description
Frequently Asked Questions
1
What is the severity of CVE-2007-0539?
CVE-2007-0539 is classified as a denial of service vulnerability.
2
How do I fix CVE-2007-0539?
To fix CVE-2007-0539, upgrade your WordPress installation to version 2.1 or later.
3
What is the impact of CVE-2007-0539?
The impact of CVE-2007-0539 can result in excessive bandwidth or thread consumption, leading to potential service outages.
4
Which versions of WordPress are affected by CVE-2007-0539?
WordPress versions prior to 2.1 are affected by CVE-2007-0539.
5
What is the primary vulnerability type of CVE-2007-0539?
The primary vulnerability type of CVE-2007-0539 is the denial of service through uncontrolled download sessions.