Description
The wp_remote_fopen function in WordPress before 2.1 allows remote attackers to cause a denial of service (bandwidth or thread consumption) via pingback service calls with a source URI that corresponds to a large file, which triggers a long download session without a timeout constraint.
Remediation
References
Related Vulnerabilities
OpenSSL Cryptographic Issues Vulnerability (CVE-2010-0928)
WordPress Plugin Slideshow Gallery LITE Multiple Vulnerabilities (1.6.8)
MySQL Improper Link Resolution Before File Access ('Link Following') Vulnerability (CVE-2016-6664)
WordPress Plugin Prismatic Multiple Cross-Site Scripting Vulnerabilities (2.7)