Otkrivena je i ispravljena jedna ranjivost u programskom paketu WordPress, namijenjenom vođenju internetskih dnevnika (blogova). Do problema dolazi u funkciji "do_trackbacks" u datoteci "wp-includes/comment.php" zbog nepravilne provjere ulaznih argumenata. Udaljeni, autenticirani napadač može iskoristiti spomenutu ranjivost za pokretanje proizvoljnih SQL naredbi pomoću polja "Send Trackbacks". Svim korisnicima se savjetuje instalacija dostupne nadogradnje koja otklanja mogućnost iskorištavanja opisanog propusta.

Fedora Update Notification
2010-12-29 21:33:52

Name        : wordpress
Product     : Fedora 13
Version     : 2.8.6
Release     : 3.fc13
URL         : http://www.wordpress.org
Summary     : WordPress blogging software
Description :
Wordpress is an online publishing / weblog package that makes it very easy,
almost trivial, to get information out to people on the web.

Update Information:

Security fix:


* Thu Dec 23 2010 Jon Ciesla <Ova e-mail adresa je zaštićena od spambota. Potrebno je omogućiti JavaScript da je vidite.> - 2.8.6-3
- Change Requires from httpd to webserver, BZ 523480.
- Patch for Hello Dolly lyrics, BZ 663966.
- Patch for security vulnerability, BZ 659319.

  [ 1 ] Bug #659265 - CVE-2010-4257 Wordpress: SQL injection flaw by processing

This update can be installed with the "yum" update program.  Use 
su -c 'yum update wordpress' at the command line.
For more information, refer to "Managing Software with yum",
available at http://docs.fedoraproject.org/yum/.

All packages are signed with the Fedora Project GPG key.  More details on the
GPG keys used by the Fedora Project can be found at
package-announce mailing list
Ova e-mail adresa je zaštićena od spambota. Potrebno je omogućiti JavaScript da je vidite.

Fedora Update Notification
2010-12-29 21:34:03

Name        : wordpress
Product     : Fedora 14
Version     : 2.8.6
Release     : 3.fc14
URL         : http://www.wordpress.org
Summary     : WordPress blogging software
Description :
Wordpress is an online publishing / weblog package that makes it very easy,
almost trivial, to get information out to people on the web.

Update Information:

Security fix:


* Thu Dec 23 2010 Jon Ciesla <Ova e-mail adresa je zaštićena od spambota. Potrebno je omogućiti JavaScript da je vidite.> - 2.8.6-3
- Change Requires from httpd to webserver, BZ 523480.
- Patch for Hello Dolly lyrics, BZ 663966.
- Patch for security vulnerability, BZ 659319.

  [ 1 ] Bug #659265 - CVE-2010-4257 Wordpress: SQL injection flaw by processing

This update can be installed with the "yum" update program.  Use 
su -c 'yum update wordpress' at the command line.
For more information, refer to "Managing Software with yum",
available at http://docs.fedoraproject.org/yum/.

All packages are signed with the Fedora Project GPG key.  More details on the
GPG keys used by the Fedora Project can be found at
package-announce mailing list
Ova e-mail adresa je zaštićena od spambota. Potrebno je omogućiti JavaScript da je vidite.

Idi na vrh