MGASA-2014-0493
Dashboard / Vulnerabilities / MGASA-2014-0493
MGASA-2014-0493
Summary: Updated wordpress package fixes security vulnerabilities
Details: XSS in wptexturize() via comments or posts, exploitable for unauthenticated users (CVE-2014-9031). XSS in media playlists (CVE-2014-9032). CSRF in the password reset process (CVE-2014-9033). Denial of service for giant passwords. The phpass library by Solar Designer was used in both projects without setting a maximum password length, which can lead to CPU exhaustion upon hashing (CVE-2014-9034). XSS in Press This (CVE-2014-9035). XSS in HTML filtering of CSS in posts (CVE-2014-9036). Hash comparison vulnerability in old-style MD5-stored passwords (CVE-2014-9037). SSRF: Safe HTTP requests did not sufficiently block the loopback IP address space (CVE-2014-9038). Previously an email address change would not invalidate a previous password reset email (CVE-2014-9039).
References: https://advisories.mageia.org/MGASA-2014-0493.html, https://bugs.mageia.org/show_bug.cgi?id=14625, https://wordpress.org/news/2014/11/wordpress-4-0-1/, http://openwall.com/lists/oss-security/2014/11/25/12
Affected packages
Package
Name: wordpress
Purl: pkg:rpm/mageia/wordpress?arch=source&distro=mageia-3
Affected ranges
Type: ECOSYSTEM
Events:
