From 4f2d7949f03e1c198bc888f2d05f421d35c57e21 Mon Sep 17 00:00:00 2001 From: V3n3RiX Date: Mon, 9 Oct 2017 18:53:29 +0100 Subject: reinit the tree, so we can have metadata --- metadata/glsa/glsa-200703-23.xml | 89 ++++++++++++++++++++++++++++++++++++++++ 1 file changed, 89 insertions(+) create mode 100644 metadata/glsa/glsa-200703-23.xml (limited to 'metadata/glsa/glsa-200703-23.xml') diff --git a/metadata/glsa/glsa-200703-23.xml b/metadata/glsa/glsa-200703-23.xml new file mode 100644 index 000000000000..652fa154c0ff --- /dev/null +++ b/metadata/glsa/glsa-200703-23.xml @@ -0,0 +1,89 @@ + + + + WordPress: Multiple vulnerabilities + + Wordpress contains several cross-site scripting, cross-site request forgery + and information leak vulnerabilities. + + wordpress + 2007-03-20 + 2007-03-20: 01 + 168529 + remote + + + 2.1.2 + + + +

+ WordPress is a popular personal publishing platform with a web + interface. +

+
+ +

+ WordPress contains cross-site scripting or cross-site scripting forgery + vulnerabilities reported by: +

+
  • g30rg3_x in the "year" + parameter of the wp_title() function
  • +
  • Alexander Concha in the + "demo" parameter of wp-admin/admin.php
  • +
  • Samenspender and Stefan + Friedli in the "post" parameter of wp-admin/post.php and + wp-admin/page.php, in the "cat_ID" parameter of wp-admin/categories.php + and in the "c" parameter of wp-admin/comment.php
  • +
  • PsychoGun in + the "file" parameter of wp-admin/templates.php
  • +

+

+

+ Additionally, WordPress prints the full PHP script paths in some error + messages. +

+
+ +

+ The cross-site scripting vulnerabilities can be triggered to steal + browser session data or cookies. A remote attacker can entice a user to + browse to a specially crafted web page that can trigger the cross-site + request forgery vulnerability and perform arbitrary WordPress actions + with the permissions of the user. Additionally, the path disclosure + vulnerability could help an attacker to perform other attacks. +

+
+ +

+ There is no known workaround at this time for all these + vulnerabilities. +

+
+ +

+ Due to the numerous recently discovered vulnerabilities in WordPress, + this package has been masked in the portage tree. All WordPress users + are advised to unmerge it. +

+ + + # emerge --unmerge "www-apps/wordpress" +
+ + CVE-2007-1049 + CVE-2007-1230 + CVE-2007-1244 + CVE-2007-1409 + SA 24430 + + + falco + + + falco + + + falco + +
-- cgit v1.2.3