• [SECURITY] [DSA 2190-1] wordpress security update

    From Giuseppe Iuculano@1:229/2 to All on Fri Mar 11 16:40:01 2011
    From: [email protected]

    -----BEGIN PGP SIGNED MESSAGE-----
    Hash: SHA1

    - ------------------------------------------------------------------------- Debian Security Advisory DSA-2190-1 [email protected] http://www.debian.org/security/ Giuseppe Iuculano
    March 11, 2011 http://www.debian.org/security/faq
    - -------------------------------------------------------------------------

    Package : wordpress
    Vulnerability : several
    Problem type : remote
    Debian-specific: no
    CVE ID : CVE-2011-0700 CVE-2011-0701


    Two XSS bugs and one potential information disclosure issue were discovered
    in wordpress, a weblog manager.
    The Common Vulnerabilities and Exposures project identifies the
    following problems:


    CVE-2011-0700

    Input passed via the post title when performing a "Quick Edit" or "Bulk Edit"
    action and via the "post_status", "comment_status", and "ping_status"
    parameters is not properly sanitised before being used.
    Certain input passed via tags in the tags meta-box is not properly sanitised
    before being returned to the user.


    CVE-2011-0701

    Wordpress incorrectly enforces user access restrictions when accessing posts
    via the media uploader and can be exploited to disclose the contents
    of e.g. private or draft posts.


    The oldstable distribution (lenny) is not affected by these problems.

    For the stable distribution (squeeze), these problems have been fixed in version 3.0.5+dfsg-0+squeeze1

    For the testing distribution (wheezy), and the unstable distribution (sid), these problems have been fixed in version 3.0.5+dfsg-1

    We recommend that you upgrade your wordpress packages.

    Further information about Debian Security Advisories, how to apply
    these updates to your system and frequently asked questions can be
    found at: http://www.debian.org/security/

    Mailing list: [email protected]

    -----BEGIN PGP SIGNATURE-----
    Version: GnuPG v1.4.11 (GNU/Linux)

    iEYEARECAAYFAk16PbkACgkQNxpp46476aqsGQCfW/YuebMZ4XYbIxw4c4EWV1Po QIkAn0+2CUrFAAscJvAdDP00D+cQE1TX
    =ZnGv
    -----END PGP SIGNATURE-----


    --
    To UNSUBSCRIBE, email to [email protected]
    with a subject of "unsubscribe". Trouble? Contact [email protected] Archive: http://lists.debian.org/[email protected]

    --- SoupGate-Win32 v1.05
    * Origin: you cannot sedate... all the things you hate (1:229/2)