Alerts This Week
Warning Icon 1 664
Alerts This Week
Warning Icon 1 664

Debian: DSA-2901-2 High Severity: WordPress Quick Drafts Regression Fix

debian
Calendar Grey April 18, 2014
Debian Logo
The Debian Advisory DSA-2901-2 addresses issues with the Quick Drafts feature in WordPress following a recent update, resolving previously encountered regressions.
The update for wordpress in DSA 2901 caused a regression in the Quick Drafts functionality

Summary

Several vulnerabilities were discovered in Wordpress, a web blogging
tool. The Common Vulnerabilities and Exposures project identifies the
following problems:

CVE-2014-0165

A user with a contributor role, using a specially crafted
request, can publish posts, which is reserved for users of the
next-higher role.

CVE-2014-0166

Jon Cave of the WordPress security team discovered that the
wp_validate_auth_cookie function in wp-includes/pluggable.php does
not properly determine the validity of authentication cookies,
allowing a remote attacker to obtain access via a forged cookie.

For the oldstable distribution (squeeze), these problems have been fixed
in version 3.6.1+dfsg-1~deb6u3.

For the stable distribution (wheezy), these problems have been fixed in
version 3.6.1+dfsg-1~deb7u3.

For the unstable distribution (sid), these problems have been fixed in
version 3.8.3+dfsg-1.

We recommend that you upgrade your wordpress packages.

Further information about Debian Security Advisories,...

Read the Full Advisory

Severity
critical
Lowest
Low
Medium
High
Critical

Package: wordpress
CVE ID: CVE-2014-0165 CVE-2014-0166

Get the latest News and Insights

Get the latest Linux and open source security news straight to your inbox.

Related News

Your message here