Debian alert DLA-2884-1 (wordpress)
| From: | Utkarsh Gupta <utkarsh@debian.org> | |
| To: | debian-lts-announce@lists.debian.org | |
| Subject: | [SECURITY] [DLA 2884-1] wordpress security update | |
| Date: | Mon, 24 Jan 2022 00:39:19 +0530 | |
| Message-ID: | <CAPP0f97V1NXUSz3tLkNDQipy9-9JHyYkDPq6Pe0bX_3Qk9_qBw@mail.gmail.com> |
-----BEGIN PGP SIGNED MESSAGE----- Hash: SHA256 - ------------------------------------------------------------------------- Debian LTS Advisory DLA-2884-1 debian-lts@lists.debian.org https://www.debian.org/lts/security/ Utkarsh Gupta January 17, 2022 https://wiki.debian.org/LTS - ------------------------------------------------------------------------- Package : wordpress Version : 4.7.22+dfsg-0+deb9u1 CVE ID : CVE-2022-21661 CVE-2022-21662 CVE-2022-21663 CVE-2022-21664 Debian Bug : 1003243 Several vulnerabilities were discovered in Wordpress, a web blogging tool. They allowed remote attackers to perform SQL injection, run unchecked SQL queries, bypass hardening, or perform Cross-Site Scripting (XSS) attacks. For Debian 9 stretch, these problems have been fixed in version 4.7.22+dfsg-0+deb9u1. We recommend that you upgrade your wordpress packages. For the detailed security status of wordpress please refer to its security tracker page at: https://security-tracker.debian.org/tracker/wordpress Further information about Debian LTS security advisories, how to apply these updates to your system and frequently asked questions can be found at: https://wiki.debian.org/LTS -----BEGIN PGP SIGNATURE----- iQIzBAEBCAAdFiEEbJ0QSEqa5Mw4X3xxgj6WdgbDS5YFAmHtp1oACgkQgj6WdgbD S5Zz2RAAlCfJ4xyFEaccC2HtcKYv0dtBTRKEGe2eqViQUjoMrvbJ+OQInE62T4fN 1A1+mvGOk2OIM6QPjIJbWFEkIxbzCLObypfhsIr4uagZmHvb+4M7n75RyRMPZ5SW P/EOkH8nEM8YvtrdWLYKB+/daG2hICZAS9lxehm0obzm20XL3eDxuLVdb2UM6Kdu J9q7/wO/dlHe5Qq0pPYU6401n/mnMYVM2W8KD8Z7FnHwBwpWJh1L8bX+ks4g1As5 28RHw0yqyMaphmwUh7wg/md4SUongQ2pgusCgjEoygkI8GLIqVlJTw8PxcVCDw05 ttAg6LDHdWG/KXc+UMSHV7cThhK9MST1MYtmbyYKUnYKLqoMVkdewnJ+3tR8trYL EUfAGSb2P/5EDMJ7n5luRLaUhKqWvC/COISJe7GC5c0arQm/ZHuF/qVYRylIUE9y wXdf5L5rDlQr3xfjRDuOxUv5EKUgwmFY8BH6duVXs9KZReeaI2wqna0BVd/I5qqo nEgAAfom4MEjz7Qh1srKwOympX8KoEweCzwtza/1Zmbq5PjYFq4XT2g3tkXH3aQJ ohVlP8FjSuHMs+liyNu/ybQ+jh7C7ufa1Mnh9pWfWV5f8HKU6G8yooJpAkU6chUg Q+geCJIMszlzkA1akDr/R6Eeo/6VCI5fKrZdxc6mwfhQEWnNybo= =QEF9 -----END PGP SIGNATURE-----
