| Summary: | wordpress new security issues fixed upstream in 3.9.8 | ||
|---|---|---|---|
| Product: | Mageia | Reporter: | David Walser <luigiwalser> |
| Component: | Security | Assignee: | QA Team <qa-bugs> |
| Status: | RESOLVED FIXED | QA Contact: | Sec team <security> |
| Severity: | normal | ||
| Priority: | Normal | CC: | davidwhodgins, sysadmin-bugs, wrw105 |
| Version: | 4 | Keywords: | validated_update |
| Target Milestone: | --- | ||
| Hardware: | i586 | ||
| OS: | Linux | ||
| URL: | http://lwn.net/Vulnerabilities/653870/ | ||
| Whiteboard: | has_procedure mga4-64-ok advisory | ||
| Source RPM: | wordpress-3.9.7-1.mga4.src.rpm | CVE: | |
| Status comment: | |||
|
Description
David Walser
2015-08-04 16:32:10 CEST
David Walser
2015-08-04 16:32:17 CEST
Whiteboard:
(none) =>
has_procedure The codex page has been updated. Advisory: ======================== Updated wordpress packages fixes security vulnerabilities: The wordpress package has been updated to version 3.9.8, fixing three cross-site scripting issues an an SQL injection issue (CVE-2015-2213), as well as other bugs. See the upstream announcement and release notes for more details. References: http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2015-2213 http://codex.wordpress.org/Version_3.9.8 https://wordpress.org/news/2015/08/wordpress-4-2-4-security-and-maintenance-release/ More CVEs: http://openwall.com/lists/oss-security/2015/08/04/7 Advisory: ======================== Updated wordpress packages fixes security vulnerabilities: The wordpress package has been updated to version 3.9.8, fixing three cross-site scripting issues (CVE-2015-5732, CVE-2015-5733, CVE-2015-5734), a potential timing side-channel attack in Customizer (CVe-2015-5730), an issue in Heartbeat where an attacker could lock a post from being edited (CVE-2015-5731), and an SQL injection issue (CVE-2015-2213), as well as other bugs. See the upstream announcement and release notes for more details. References: http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2015-2213 http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2015-5730 http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2015-5731 http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2015-5732 http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2015-5733 http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2015-5734 http://codex.wordpress.org/Version_3.9.8 https://wordpress.org/news/2015/08/wordpress-4-2-4-security-and-maintenance-release/ http://openwall.com/lists/oss-security/2015/08/04/7
David Walser
2015-08-07 21:36:03 CEST
URL:
(none) =>
http://lwn.net/Vulnerabilities/653870/ Tested on a new install mga4-64. Set up wordpress, wrote a post and a page, edited post and a page, created a user and changed role. All OK. As this is a noarch package, validating. Keywords:
(none) =>
validated_update
Dave Hodgins
2015-08-09 10:33:38 CEST
CC:
(none) =>
davidwhodgins An update for this issue has been pushed to Mageia Updates repository. http://advisories.mageia.org/MGASA-2015-0309.html Status:
NEW =>
RESOLVED |