[arch-security] [ASA-201609-4] wordpress: multiple issues
Arch Linux Security Advisory ASA-201609-4 ========================================= Severity: High Date : 2016-09-09 CVE-ID : CVE-2016-7168 CVE-2016-7169 Package : wordpress Type : multiple issues Remote : Yes Link : https://wiki.archlinux.org/index.php/CVE Summary ======= The package wordpress before version 4.6-1 is vulnerable to multiple issues. Resolution ========== Upgrade to 4.6-1. # pacman -Syu "wordpress>=4.6-1" The problem has been fixed upstream in version 4.6. Workaround ========== None. Description =========== - CVE-2016-7168 (cross-site scripting) A cross-site scripting vulnerability via an image filename, reported by SumOfPwm researcher Cengiz Han Sahin. - CVE-2016-7169 (directory traversal) A directory traversal vulnerability in the upgrade package uploader, reported by Dominik Schilling from the Wordpress security team. Impact ====== A remote attacker can perform a presistent cross-site scripting attack on a WordPress installation or perform directory traversal. References ========== https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2016-7168 https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2016-7169 http://www.openwall.com/lists/oss-security/2016/09/08/19 https://wordpress.org/news/2016/09/wordpress-4-6-1-security-and-maintenance-... https://sumofpwn.nl/advisory/2016/persistent_cross_site_scripting_vulnerabil...
participants (1)
-
Jelle van der Waa