Candidate: CVE-2013-2173 PublicDate: 2013-06-21 13:57:00 UTC References: https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2013-2173 http://www.openwall.com/lists/oss-security/2013/06/12 Description: wp-includes/class-phpass.php in WordPress 3.5.1, when a password-protected post exists, allows remote attackers to cause a denial of service (CPU consumption) via a crafted value of a certain wp-postpass cookie. Ubuntu-Description: Notes: Bugs: Priority: medium Discovered-by: Assigned-to: CVSS: Patches_wordpress: upstream_wordpress: released (3.5.2+dfsg-1) lucid_wordpress: ignored (reached end-of-life) precise_wordpress: ignored (reached end-of-life) precise/esm_wordpress: DNE (precise was needed) quantal_wordpress: ignored (reached end-of-life) raring_wordpress: ignored (reached end-of-life) saucy_wordpress: ignored (reached end-of-life) trusty_wordpress: not-affected (3.8.2+dfsg-1ubuntu0.1) trusty/esm_wordpress: DNE (trusty was not-affected [3.8.2+dfsg-1ubuntu0.1]) utopic_wordpress: ignored (reached end-of-life) vivid_wordpress: ignored (reached end-of-life) vivid/stable-phone-overlay_wordpress: DNE vivid/ubuntu-core_wordpress: DNE wily_wordpress: ignored (reached end-of-life) xenial_wordpress: not-affected (4.4.2+dfsg-1ubuntu1) yakkety_wordpress: ignored (reached end-of-life) zesty_wordpress: ignored (reached end-of-life) artful_wordpress: ignored (reached end-of-life) bionic_wordpress: not-affected (4.9.5+dfsg1-1) devel_wordpress: not-affected (4.9.7+dfsg1-1)