CVE-2009-3622

Algorithmic complexity vulnerability in wp-trackback.php in WordPress before 2.8.5 allows remote attackers to cause a denial of service (CPU consumption and server hang) via a long title parameter in conjunction with a charset parameter composed of many comma-separated "UTF-8" substrings, related to the mb_convert_encoding function in PHP.

Date published : 2009-10-23

http://wordpress.org/development/2009/10/wordpress-2-8-5-hardening-release/

https://bugzilla.redhat.com/show_bug.cgi?id=530056