CVE-2014-5265: Medium severity wordpress vulnerability
The Incutio XML-RPC (IXR) Library, as used in WordPress before 3.9.2 and Drupal 6.x before 6.33 and 7.x before 7.31, permits entity declarations without considering recursion during entity expansion, which allows remote attackers to cause a denial of service (memory and CPU consumption) via a crafted XML document containing a large number of nested entity references, a similar issue to CVE-2003-1564.
Affected Software
Remediation
Patch Available
Patch Available
Event History
Frequently Asked Questions
What is the severity of CVE-2014-5265?
CVE-2014-5265 is classified as a medium severity vulnerability due to its potential for denial of service attacks.
How do I fix CVE-2014-5265?
To fix CVE-2014-5265, update to WordPress version 3.9.2 or higher or Drupal version 6.33 or 7.31 or higher.
Who is affected by CVE-2014-5265?
CVE-2014-5265 affects WordPress versions prior to 3.9.2 and Drupal versions prior to 6.33 and 7.31.
What is the impact of CVE-2014-5265?
The impact of CVE-2014-5265 allows remote attackers to cause denial of service by exhausting memory and CPU resources.
How does CVE-2014-5265 exploit the XML-RPC library?
CVE-2014-5265 exploits the XML-RPC library by permitting recursive entity declarations that lead to excessive resource consumption.