Alerts This Week
Warning Icon 1 619
Alerts This Week
Warning Icon 1 619

Debian: DSA-2190-1 Moderate: WordPress XSS And Access Disclosure

debian
Calendar Grey March 11, 2011
Debian Logo
-----BEGIN PGP SIGNED MESSAGE----- Hash: SHA1 - ----------------------------------------------------
Two XSS bugs and one potential information disclosure issue were discovered in wordpress, a weblog manager

Summary


Two XSS bugs and one potential information disclosure issue were discovered
in wordpress, a weblog manager.
The Common Vulnerabilities and Exposures project identifies the
following problems:


CVE-2011-0700

Input passed via the post title when performing a "Quick Edit" or "Bulk Edit"
action and via the "post_status", "comment_status", and "ping_status"
parameters is not properly sanitised before being used.
Certain input passed via tags in the tags meta-box is not properly sanitised
before being returned to the user.


CVE-2011-0701

Wordpress incorrectly enforces user access restrictions when accessing posts
via the media uploader and can be exploited to disclose the contents
of e.g. private or draft posts.


The oldstable distribution (lenny) is not affected by these problems.

For the stable distribution (squeeze), these problems have been fixed in
version 3.0.5+dfsg-0+squeeze1

For the testing distribution (wheezy), and the unstable distribution (sid),
these problems have been fixed in ve...

Read the Full Advisory

Package: wordpress
CVE ID: CVE-2011-0700 CVE-2011-0701

Get the latest News and Insights

Get the latest Linux and open source security news straight to your inbox.

Related News

Your message here