Bug 16531 - wordpress new security issues fixed upstream in 3.9.8
Summary: wordpress new security issues fixed upstream in 3.9.8
Status: RESOLVED FIXED
Alias: None
Product: Mageia
Classification: Unclassified
Component: Security (show other bugs)
Version: 4
Hardware: i586 Linux
Priority: Normal normal
Target Milestone: ---
Assignee: QA Team
QA Contact: Sec team
URL: http://lwn.net/Vulnerabilities/653870/
Whiteboard: has_procedure mga4-64-ok advisory
Keywords: validated_update
Depends on:
Blocks:
 
Reported: 2015-08-04 16:32 CEST by David Walser
Modified: 2015-08-10 16:33 CEST (History)
3 users (show)

See Also:
Source RPM: wordpress-3.9.7-1.mga4.src.rpm
CVE:
Status comment:


Attachments

Description David Walser 2015-08-04 16:32:10 CEST
Upstream has announced new versions today (August 4):
https://wordpress.org/news/2015/08/wordpress-4-2-4-security-and-maintenance-release/

The issue was fixed upstream in versions 4.2.4 and 3.9.8:
http://codex.wordpress.org/Version_3.9.8

CVE request:
http://openwall.com/lists/oss-security/2015/08/04/5

Generic advisory for now, pending CVE assignments.

Updated package uploaded for Mageia 4.

Testing procedure:
https://bugs.mageia.org/show_bug.cgi?id=14625#c4

Advisory:
========================

Updated wordpress packages fixes security vulnerabilities:

The wordpress package has been updated to version 3.9.8, fixing multiple
security issues and other bugs.  See the upstream announcement and release
notes for more details.

References:
http://codex.wordpress.org/Version_3.9.8
https://wordpress.org/news/2015/08/wordpress-4-2-4-security-and-maintenance-release/
========================

Updated packages in core/updates_testing:
========================
wordpress-3.9.8-1.mga4

from wordpress-3.9.8-1.mga4.src.rpm

Reproducible: 

Steps to Reproduce:
David Walser 2015-08-04 16:32:17 CEST

Whiteboard: (none) => has_procedure

Comment 1 David Walser 2015-08-04 17:40:18 CEST
The codex page has been updated.

Advisory:
========================

Updated wordpress packages fixes security vulnerabilities:

The wordpress package has been updated to version 3.9.8, fixing three
cross-site scripting issues an an SQL injection issue (CVE-2015-2213), as well
as other bugs.  See the upstream announcement and release notes for more
details.

References:
http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2015-2213
http://codex.wordpress.org/Version_3.9.8
https://wordpress.org/news/2015/08/wordpress-4-2-4-security-and-maintenance-release/
Comment 2 David Walser 2015-08-04 20:55:37 CEST
More CVEs:
http://openwall.com/lists/oss-security/2015/08/04/7

Advisory:
========================

Updated wordpress packages fixes security vulnerabilities:

The wordpress package has been updated to version 3.9.8, fixing three
cross-site scripting issues (CVE-2015-5732, CVE-2015-5733, CVE-2015-5734),
a potential timing side-channel attack in Customizer (CVe-2015-5730), an
issue in Heartbeat where an attacker could lock a post from being edited
(CVE-2015-5731), and an SQL injection issue (CVE-2015-2213), as well
as other bugs.  See the upstream announcement and release notes for more
details.

References:
http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2015-2213
http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2015-5730
http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2015-5731
http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2015-5732
http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2015-5733
http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2015-5734
http://codex.wordpress.org/Version_3.9.8
https://wordpress.org/news/2015/08/wordpress-4-2-4-security-and-maintenance-release/
http://openwall.com/lists/oss-security/2015/08/04/7
David Walser 2015-08-07 21:36:03 CEST

URL: (none) => http://lwn.net/Vulnerabilities/653870/

Comment 3 Bill Wilkinson 2015-08-08 15:38:01 CEST
Tested on a new install mga4-64.

Set up wordpress, wrote a post and a page, edited post and a page, created a user and changed role.  All OK.

As this is a noarch package, validating.

Keywords: (none) => validated_update
Whiteboard: has_procedure => has_procedure mga4-64-ok
CC: (none) => wrw105, sysadmin-bugs

Dave Hodgins 2015-08-09 10:33:38 CEST

CC: (none) => davidwhodgins
Whiteboard: has_procedure mga4-64-ok => has_procedure mga4-64-ok advisory

Comment 4 Mageia Robot 2015-08-10 16:33:13 CEST
An update for this issue has been pushed to Mageia Updates repository.

http://advisories.mageia.org/MGASA-2015-0309.html

Status: NEW => RESOLVED
Resolution: (none) => FIXED


Note You need to log in before you can comment on or make changes to this bug.