Debian Security Advisory

DSA-2138-1 wordpress -- SQL injection

Date Reported:
29 Dec 2010
Affected Packages:
wordpress
Vulnerable:
Yes
Security database references:
In Mitre's CVE dictionary: CVE-2010-4257.
More information:

Vladimir Kolesnikov discovered a SQL injection vulnerability in WordPress, a weblog manager. An authenticated user could execute arbitrary SQL commands via the Send Trackbacks field.

For the stable distribution (lenny), this problem has been fixed in version 2.5.1-11+lenny4.

For the unstable distribution (sid), and the testing distribution (squeeze), this problem has been fixed in version 3.0.2-1.

We recommend that you upgrade your wordpress package.

Further information about Debian Security Advisories, how to apply these updates to your system and frequently asked questions can be found at: https://www.debian.org/security/