Bug 16763 - wordpress new security issues fixed upstream in 3.9.9 (CVE-2015-5714, CVE-2015-5715)
Summary: wordpress new security issues fixed upstream in 3.9.9 (CVE-2015-5714, CVE-201...
Status: RESOLVED FIXED
Alias: None
Product: Mageia
Classification: Unclassified
Component: Security (show other bugs)
Version: 4
Hardware: i586 Linux
Priority: Normal normal
Target Milestone: ---
Assignee: QA Team
QA Contact: Sec team
URL: http://lwn.net/Vulnerabilities/657812/
Whiteboard: has_procedure advisory mga4-64-ok
Keywords: validated_update
Depends on:
Blocks:
 
Reported: 2015-09-15 23:28 CEST by David Walser
Modified: 2015-09-18 17:43 CEST (History)
2 users (show)

See Also:
Source RPM: wordpress-3.9.8-1.mga4.src.rpm
CVE:
Status comment:


Attachments

Description David Walser 2015-09-15 23:28:04 CEST
Upstream has released versions 3.9.9 and 4.3.1 today (September 15):
https://codex.wordpress.org/Version_3.9.9
https://wordpress.org/news/2015/09/wordpress-4-3-1/

They fix two XSS issues and a potential privilege escalation issue.

Updated package uploaded for Mageia 4.

Testing procedure:
https://bugs.mageia.org/show_bug.cgi?id=14625#c4

Advisory:
========================

Updated wordpress packages fixes security vulnerabilities:

The wordpress package has been updated to version 3.9.9, fixing two
cross-site scripting issues and a potential privilege escalation issue
(CVE-2015-5714, CVE-2015-5715), as well as other bugs.  See the upstream
announcement and release notes for more details.

References:
http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2015-5714
http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2015-5715
https://codex.wordpress.org/Version_3.9.9
https://wordpress.org/news/2015/09/wordpress-4-3-1/
========================

Updated packages in core/updates_testing:
========================
wordpress-3.9.9-1.mga4

from wordpress-3.9.9-1.mga4.src.rpm

Reproducible: 

Steps to Reproduce:
David Walser 2015-09-15 23:28:12 CEST

Whiteboard: (none) => has_procedure

Comment 1 Bill Wilkinson 2015-09-16 17:25:23 CEST
Created and edited a page and a post, created and deleted a user, viewed pages all OK.

Validating as this is a noarch package. Ready for push when advisory uploaded to svn.

Keywords: (none) => validated_update
Whiteboard: has_procedure => has_procedure mga4-64-ok
CC: (none) => wrw105, sysadmin-bugs

Comment 2 claire robinson 2015-09-17 16:51:06 CEST
Advisory uploaded.

Whiteboard: has_procedure mga4-64-ok => has_procedure advisory mga4-64-ok

Comment 3 Mageia Robot 2015-09-17 20:03:33 CEST
An update for this issue has been pushed to Mageia Updates repository.

http://advisories.mageia.org/MGASA-2015-0377.html

Status: NEW => RESOLVED
Resolution: (none) => FIXED

David Walser 2015-09-18 17:43:03 CEST

URL: (none) => http://lwn.net/Vulnerabilities/657812/


Note You need to log in before you can comment on or make changes to this bug.