From dd0b51927f91f7d4aedf5398a707cf52b2a01d2a Mon Sep 17 00:00:00 2001 From: Neil McGovern Date: Sat, 3 Mar 2007 20:06:33 +0000 Subject: Release wordpress/DTSA-34-1 git-svn-id: svn+ssh://svn.debian.org/svn/secure-testing@5502 e39458fd-73e7-0310-bf30-c45bca0a0e42 --- website/DTSA/DTSA-34-1.html | 93 +++++++++++++++++++++++++++++++++++++++++++++ website/list.html | 2 + 2 files changed, 95 insertions(+) create mode 100644 website/DTSA/DTSA-34-1.html (limited to 'website') diff --git a/website/DTSA/DTSA-34-1.html b/website/DTSA/DTSA-34-1.html new file mode 100644 index 0000000000..6c0d570f91 --- /dev/null +++ b/website/DTSA/DTSA-34-1.html @@ -0,0 +1,93 @@ + + + Debian testing security team - Advisory + + + + +
+ + + + + Debian Project +
+
+ + + + + + + + + + + +
+ Debian testing security team - Advisory +
+ + +
+ + +

DTSA-34-1

+
+
Date Reported:
+
March 3rd, 2007
+
Affected Package:
+
wordpress
+
Vulnerability:
+
cross-site scripting
+
Problem-Scope:
+
remote
+
Debian-specific:
+
No
+
CVE:
+
+CVE-2007-1049 +
+
More information:
+
A Cross-site scripting (XSS) vulnerability in the wp_explain_nonce function in 
+the nonce AYS functionality (wp-includes/functions.php) for WordPress 2.0 
+before 2.0.9 and 2.1 before 2.1.1 allows remote attackers to inject arbitrary 
+web script or HTML via the file parameter to wp-admin/templates.php, and 
+possibly other vectors involving the action variable. 

+Please note that wordpress is not present in sarge. 
+
+
For the testing distribution (etch) this is fixed in version 2.0.9-1
+
For the unstable distribution (sid) this is fixed in version 2.1.1-1
+
This upgrade is recommended if you use wordpress.
+
If you have the secure testing lines in your sources.list, you can update by running this command as root:
+ +
apt-get update && apt-get install wordpress
+
+ +
+
To use the Debian testing security archive, add the following lines to your /etc/apt/sources.list:
+
+
deb http://security.debian.org/ testing/updates main contrib non-free
+
deb-src http://security.debian.org/ testing/updates main contrib non-free
+
+
The archive signing key can be downloaded from
+
http://secure-testing.debian.net/ziyi-2005-7.asc
+ +
+ + +
+ + Valid HTML 4.01! + + Valid CSS! + + + + diff --git a/website/list.html b/website/list.html index ce754ebe12..1a3f48155e 100644 --- a/website/list.html +++ b/website/list.html @@ -99,6 +99,8 @@
programming error
[February 12th, 2007] DTSA-33-1 wordpress
multiple vulnerabilities
+
[March 3rd, 2007] DTSA-34-1 wordpress
+
cross-site scripting

-- cgit v1.2.3