|
|
Log in / Subscribe / Register

Debian alert DLA-2208-1 (wordpress)

From:  Utkarsh Gupta <utkarsh@debian.org>
To:  debian-lts-announce@lists.debian.org
Subject:  [SECURITY] [DLA 2208-1] wordpress security update
Date:  Mon, 11 May 2020 19:13:12 +0530
Message-ID:  <f95dcebe-78cf-bae7-4b3e-2205f71f4719@debian.org>

-----BEGIN PGP SIGNED MESSAGE----- Hash: SHA256 Package : wordpress Version : 4.1.30+dfsg-0+deb8u1 CVE ID : CVE-2020-11026 CVE-2020-11027 CVE-2020-11028 CVE-2020-11029 Debian Bug : 959391 Multiple CVE(s) were discovered in the src:wordpress package. CVE-2020-11026 Files with a specially crafted name when uploaded to the Media section can lead to script execution upon accessing the file. This requires an authenticated user with privileges to upload files. CVE-2020-11027 A password reset link emailed to a user does not expire upon changing the user password. Access would be needed to the email account of the user by a malicious party for successful execution. CVE-2020-11028 Some private posts, which were previously public, can result in unauthenticated disclosure under a specific set of conditions. CVE-2020-11029 A vulnerability in the stats() method of class-wp-object-cache.php can be exploited to execute cross-site scripting (XSS) attacks. For Debian 8 "Jessie", these problems have been fixed in version 4.1.30+dfsg-0+deb8u1. We recommend that you upgrade your wordpress packages. Further information about Debian LTS security advisories, how to apply these updates to your system and frequently asked questions can be found at: https://wiki.debian.org/LTS Best, Utkarsh -----BEGIN PGP SIGNATURE----- iQIzBAEBCAAdFiEEbJ0QSEqa5Mw4X3xxgj6WdgbDS5YFAl65Vl0ACgkQgj6WdgbD S5b3+g/+JP5/nEpFx+4NhWVR3BEvWeViZeFi0T6LujRITUO6A5agZ74qRFHld9UF fFm40/G7Vpn4Oe4+WAr6yZLdDO3npT4iBBcaPYTQtr0EJGE6/tDf3AvfXdQ3CHsX uaIZQFRR3H+uyJV4UsFml+NMO+AyrjJMG1Nh8e2Wo2r3WD++gbyZbnjQJ3IZFRkk +UPCBcmPDTo09y9gF4/jTJ0FpfrzVw53XtppGizEH44OSFtywN8t09xZpDTKOGm5 S8aB2Dr8giIyku2nm5VZJ740nMb/q1RcC3krLJYXXIemvvmzjPb69f9B8aI8Mt6Y IXYMwmRLsKCW+pRv8TymM9WByhlONUeVqvOv0tfIXiHnJrGaRzfuYmEb4L72msnf P0OVo0CL8D5QwYe4OwelczXooV0plEpQ2OTn699QtEpPGt28W6TI0yLk9m1wEjUp Bp/g+R5dFYJCKd7MEEnfDRQjakCmTwRxsaXk29WK6KVPPsdoTDSsIj4MIndy7NzX fTCLqaY1noku3MtpHiHIYtac6JLmBkPDBMh11bzA0l2Tcnoq+bUNgo6fWQHtP6fO Kt4CG1f2NcktiRupNw6+wdGMgd6LdX+RG91uxe7mGYQ0N03PtjTqclBi0VR87MVP /VyOdPnL2YrDDCNPwMJOl/P/V+Ci586ajfdxQbNV8oKduo8ZnKs= =qwxr -----END PGP SIGNATURE-----


to post comments


Copyright © 2026, Eklektix, Inc.
Comments and public postings are copyrighted by their creators.
Linux is a registered trademark of Linus Torvalds