Description
The URI.decode_www_form_component method in Ruby before 1.9.2-p330 allows remote attackers to cause a denial of service (catastrophic regular expression backtracking, resource consumption, or application crash) via a crafted string.
Remediation
References
Related Vulnerabilities
WordPress Exposure of Sensitive Information to an Unauthorized Actor Vulnerability (CVE-2012-5868)
WordPress Plugin Newsletter Subscription Form Possible Remote Code Execution (1.1.2)
WordPress Plugin Quick Event Manager Cross-Site Scripting (9.6.4)
WordPress Plugin GNU-Mailman Integration Cross-Site Scripting (1.0.6)