Debian Security Advisory
DSA-3997-1 wordpress -- security update
- Date Reported:
- 10 Oct 2017
- Affected Packages:
- wordpress
- Vulnerable:
- Yes
- Security database references:
- In the Debian bugtracking system: Bug 876274, Bug 877629.
In Mitre's CVE dictionary: CVE-2017-14718, CVE-2017-14719, CVE-2017-14720, CVE-2017-14721, CVE-2017-14722, CVE-2017-14723, CVE-2017-14724, CVE-2017-14725, CVE-2017-14726, CVE-2017-14990. - More information:
-
Several vulnerabilities were discovered in Wordpress, a web blogging tool. They would allow remote attackers to exploit path-traversal issues, perform SQL injections and various cross-site scripting attacks.
For the oldstable distribution (jessie), these problems have been fixed in version 4.1+dfsg-1+deb8u15.
For the stable distribution (stretch), these problems have been fixed in version 4.7.5+dfsg-2+deb9u1.
For the testing distribution (buster), these problems have been fixed in version 4.8.2+dfsg-2.
For the unstable distribution (sid), these problems have been fixed in version 4.8.2+dfsg-2.
We recommend that you upgrade your wordpress packages.