[Date Prev][Date Next] [Thread Prev][Thread Next] [Date Index] [Thread Index]

[SECURITY] [DLA 2208-1] wordpress security update



-----BEGIN PGP SIGNED MESSAGE-----
Hash: SHA256

Package        : wordpress
Version        : 4.1.30+dfsg-0+deb8u1
CVE ID         : CVE-2020-11026 CVE-2020-11027 CVE-2020-11028
                 CVE-2020-11029
Debian Bug     : 959391


Multiple CVE(s) were discovered in the src:wordpress package.

CVE-2020-11026

    Files with a specially crafted name when uploaded to the
    Media section can lead to script execution upon accessing
    the file. This requires an authenticated user with privileges
    to upload files.

CVE-2020-11027

    A password reset link emailed to a user does not expire upon
    changing the user password. Access would be needed to the email
    account of the user by a malicious party for successful execution.

CVE-2020-11028

    Some private posts, which were previously public, can result in
    unauthenticated disclosure under a specific set of conditions.

CVE-2020-11029

    A vulnerability in the stats() method of class-wp-object-cache.php
    can be exploited to execute cross-site scripting (XSS) attacks.

For Debian 8 "Jessie", these problems have been fixed in version
4.1.30+dfsg-0+deb8u1.

We recommend that you upgrade your wordpress packages.

Further information about Debian LTS security advisories, how to apply
these updates to your system and frequently asked questions can be
found at: https://wiki.debian.org/LTS


Best,
Utkarsh
-----BEGIN PGP SIGNATURE-----

iQIzBAEBCAAdFiEEbJ0QSEqa5Mw4X3xxgj6WdgbDS5YFAl65Vl0ACgkQgj6WdgbD
S5b3+g/+JP5/nEpFx+4NhWVR3BEvWeViZeFi0T6LujRITUO6A5agZ74qRFHld9UF
fFm40/G7Vpn4Oe4+WAr6yZLdDO3npT4iBBcaPYTQtr0EJGE6/tDf3AvfXdQ3CHsX
uaIZQFRR3H+uyJV4UsFml+NMO+AyrjJMG1Nh8e2Wo2r3WD++gbyZbnjQJ3IZFRkk
+UPCBcmPDTo09y9gF4/jTJ0FpfrzVw53XtppGizEH44OSFtywN8t09xZpDTKOGm5
S8aB2Dr8giIyku2nm5VZJ740nMb/q1RcC3krLJYXXIemvvmzjPb69f9B8aI8Mt6Y
IXYMwmRLsKCW+pRv8TymM9WByhlONUeVqvOv0tfIXiHnJrGaRzfuYmEb4L72msnf
P0OVo0CL8D5QwYe4OwelczXooV0plEpQ2OTn699QtEpPGt28W6TI0yLk9m1wEjUp
Bp/g+R5dFYJCKd7MEEnfDRQjakCmTwRxsaXk29WK6KVPPsdoTDSsIj4MIndy7NzX
fTCLqaY1noku3MtpHiHIYtac6JLmBkPDBMh11bzA0l2Tcnoq+bUNgo6fWQHtP6fO
Kt4CG1f2NcktiRupNw6+wdGMgd6LdX+RG91uxe7mGYQ0N03PtjTqclBi0VR87MVP
/VyOdPnL2YrDDCNPwMJOl/P/V+Ci586ajfdxQbNV8oKduo8ZnKs=
=qwxr
-----END PGP SIGNATURE-----


Reply to: