Description
file before 5.19 does not properly restrict the amount of data read during a regex search, which allows remote attackers to cause a denial of service (CPU consumption) via a crafted file that triggers backtracking during processing of an awk rule. NOTE: this vulnerability exists because of an incomplete fix for CVE-2013-7345.
Remediation
References
Related Vulnerabilities
WordPress Plugin YITH WooCommerce Added to Cart Popup Security Bypass (1.3.11)
WordPress Plugin WPMovieLibrary Multiple Cross-Site Scripting Vulnerabilities (2.1.4.1)
WordPress Plugin Student Result or Employee Database Security Bypass (1.6.3)
WordPress Plugin rtMedia for WordPress, BuddyPress and bbPress Cross-Site Scripting (3.7.38)
WordPress Plugin Elementor Website Builder Cross-Site Scripting (2.9.13)