Debian alert DLA-2429-1 (wordpress)
| From: | Utkarsh Gupta <utkarsh@debian.org> | |
| To: | debian-lts-announce@lists.debian.org | |
| Subject: | [SECURITY] [DLA 2429-1] wordpress security update | |
| Date: | Tue, 03 Nov 2020 12:49:50 +0530 | |
| Message-ID: | <CAPP0f96exVHS4mXdw2wdCD5M18dv_ZzGcuTv5tkKKJB3T4SBVQ@mail.gmail.com> |
-----BEGIN PGP SIGNED MESSAGE----- Hash: SHA256 - ----------------------------------------------------------------------- Debian LTS Advisory DLA-2429-1 debian-lts@lists.debian.org https://www.debian.org/lts/security/ Utkarsh Gupta November 03, 2020 https://wiki.debian.org/LTS - ----------------------------------------------------------------------- Package : wordpress Version : 4.7.19+dfsg-1+deb9u1 CVE ID : CVE-2020-28032 CVE-2020-28033 CVE-2020-28034 CVE-2020-28035 CVE-2020-28036 CVE-2020-28037 CVE-2020-28038 CVE-2020-28039 CVE-2020-28040 Debian Bug : 973562 There were several vulnerabilites reported against wordpress, as follows: CVE-2020-28032 WordPress before 4.7.19 mishandles deserialization requests in wp-includes/Requests/Utility/FilteredIterator.php. CVE-2020-28033 WordPress before 4.7.19 mishandles embeds from disabled sites on a multisite network, as demonstrated by allowing a spam embed. CVE-2020-28034 WordPress before 4.7.19 allows XSS associated with global variables. CVE-2020-28035 WordPress before 4.7.19 allows attackers to gain privileges via XML-RPC. CVE-2020-28036 wp-includes/class-wp-xmlrpc-server.php in WordPress before 4.7.19 allows attackers to gain privileges by using XML-RPC to comment on a post. CVE-2020-28037 is_blog_installed in wp-includes/functions.php in WordPress before 4.7.19 improperly determines whether WordPress is already installed, which might allow an attacker to perform a new installation, leading to remote code execution (as well as a denial of service for the old installation). CVE-2020-28038 WordPress before 4.7.19 allows stored XSS via post slugs. CVE-2020-28039 is_protected_meta in wp-includes/meta.php in WordPress before 4.7.19 allows arbitrary file deletion because it does not properly determine whether a meta key is considered protected. CVE-2020-28040 WordPress before 4.7.19 allows CSRF attacks that change a theme's background image. For Debian 9 stretch, these problems have been fixed in version 4.7.19+dfsg-1+deb9u1. We recommend that you upgrade your wordpress packages. For the detailed security status of wordpress please refer to its security tracker page at: https://security-tracker.debian.org/tracker/wordpress Further information about Debian LTS security advisories, how to apply these updates to your system and frequently asked questions can be found at: https://wiki.debian.org/LTS -----BEGIN PGP SIGNATURE----- iQIzBAEBCAAdFiEEbJ0QSEqa5Mw4X3xxgj6WdgbDS5YFAl+hBH8ACgkQgj6WdgbD S5ZNiRAAhvMgDgEq7AnOBojmHqoVB1xDnJ5jGhPwEUDvuuAHBxD4FM0KU66oEY3c n2kp0Cuhh/V3oeUoH2neohhIi1wbnD0voRTIcWZAqLSVJGCoyjbVH3mCIDj95UiL E7+/FqYhWWqvWtrQkFzKUfvo4GwrYj/aFv4n1njSxjjN8fkm2loxO9yHy/F4nBhx 5OEE/H4xmzBYS8bMKDmtDiJQxblRq4h9oIRKXl2PS/VMuFvSVI92cp9LTSJZeqkN OGqQQt3OVpIYTb6OUs1b/HgOxjieLktBac2OaTkfUweOMQNWwgKudVQix1KQCYE8 FTf9ub/CafVSigaDo93qzNLjsiTfaJuEKtSem7RfQfyrZf8IjyeeVRuXNT3Tivgr /xu2ieJcDOPWBIXYzNg9xTlsSoSHsZuXcym0kxbM4vnQmVOdqgePCaCD+oUanwik Ltt+2r1KOoJHm8DCCRdEbZcATze4gMZqk9WcpOG/vS+PmKP2HDbUrezLxfVjCO5J RV1ql8jDAGJRWNDCTRO2KIkv1LwNfVEtRCeMM9ddin7JTPWxKRFcNeUNuAQqqhw0 r6/m+QeSdqy687S7B8Jln5kWa6K6TOx81nINaZJs5YD2cpKyKIKcodQVocQj0iwb X9Y4usCGqj3ZWFlQoX7nrVwREGYJA8m8snzv83nnFbR4JUJREuY= =aMvT -----END PGP SIGNATURE-----
