Alerts This Week
Warning Icon 1 664
Alerts This Week
Warning Icon 1 664

Debian: DSA-3085-1 Moderate: Risks of WordPress DoS Vulnerabilities

debian
Calendar Grey December 3, 2014
Debian Logo
Several WordPress vulnerabilities pose significant DDoS and data leak threats. Promptly update to safeguard your site.
Multiple security issues have been discovered in Wordpress, a web blogging tool, resulting in denial of service or information disclosure

Summary

Multiple security issues have been discovered in Wordpress, a web
blogging tool, resulting in denial of service or information disclosure.
More information can be found in the upstream advisory at
https://wordpress.org/news/2014/11/wordpress-4-0-1/

CVE-2014-9031

Jouko Pynnonen discovered an unauthenticated cross site scripting
vulnerability (XSS) in wptexturize(), exploitable via comments or
posts.

CVE-2014-9033

Cross site request forgery (CSRF) vulnerability in the password
changing process, which could be used by an attacker to trick an
user into changing her password.

CVE-2014-9034

Javier Nieto Arevalo and Andres Rojas Guerrero reported a potential
denial of service in the way the phpass library is used to handle
passwords, since no maximum password length was set.

CVE-2014-9035

John Blackbourn reported an XSS in the "Press This" function (used
for quick publishing using a browser "bookmarklet").

CVE-2014-9036

Robert Chapin reported an XSS in the HTML ...

Read the Full Advisory

Package: wordpress
CVE ID: CVE-2014-9031 CVE-2014-9033 CVE-2014-9034 CVE-2014-9035

Get the latest News and Insights

Get the latest Linux and open source security news straight to your inbox.

Related News

Your message here