Bug List: (This bug is not in your last search results)   Show last search results      Search page      Enter new bug
Bug#: 142142
Alias:
Product:
Component:
Status: CLOSED
Resolution: FIXED
Assigned To: Gentoo Security <security@gentoo.org>
Hardware:
OS:
Version:
Priority:
Severity:
Reporter: Aaron Kulbe (RETIRED) <superlag@gentoo.org>
Add CC:
CC:
URL:
Summary:
Status Whiteboard:
Keywords:
Flags: Requestee:
 
 
  ()

Filename Description Type Creator Created Size Actions
Create a New Attachment (proposed patch, testcase, etc.) View All

Bug 142142 depends on: Show dependency tree
Bug 142142 blocks:

Additional Comments: (this is where you put emerge --info)


Not eligible to see or edit group visibility for this bug.




View Bug Activity   |   Format For Printing   |   XML   |   Clone This Bug


Description:   Opened: 2006-07-29 19:45 0000
Version 2.0.4 fixes some bugs.  Bump.

------- Comment #1 From Aaron Kulbe (RETIRED) 2006-07-29 19:49:05 0000 -------
Done.

------- Comment #2 From Aaron Kulbe (RETIRED) 2006-07-30 17:09:34 0000 -------
An ebuild name would help....


www-apps/wordpress

bumped from 2.0.3 to 2.0.4

------- Comment #3 From Matthias Geerdsen 2006-07-31 05:38:54 0000 -------
taking over the bug since 2.0.4 fixes security issues

"WordPress 2.0.4, the latest stable release in our Duke series, is available
for immediate download. This release contains several important security fixes,
so it

------- Comment #4 From Matthias Geerdsen 2006-07-31 05:38:54 0000 -------
taking over the bug since 2.0.4 fixes security issues

"WordPress 2.0.4, the latest stable release in our Duke series, is available
for immediate download. This release contains several important security fixes,
so it’s highly recommended for all users. We’ve also rolled in a number of
bug fixes (over 50!), so it’s a pretty solid release across the board."

arches, please test and mark wordpress-2.0.4 stable if possible

------- Comment #5 From Wolf Giesen (RETIRED) 2006-07-31 05:49:27 0000 -------
2.0.3 is affected by
http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2006-3390 and
http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2006-3389

Which sounds like B3/minor to me.

------- Comment #6 From Matthias Geerdsen 2006-07-31 05:51:32 0000 -------
oh and there is this... "announcement"

http://unknowngenius.com/blog/archives/2006/07/26/critical-announcement-to-all-wordpress-users/

------- Comment #7 From René Nussbaumer 2006-07-31 10:12:20 0000 -------
stable on hppa

------- Comment #8 From Tobias Scherbaum 2006-07-31 11:00:57 0000 -------
ppc stable

------- Comment #9 From Joshua Jackson 2006-07-31 20:11:32 0000 -------
x86 is gone ^.^

------- Comment #10 From Wolf Giesen (RETIRED) 2006-08-02 02:09:04 0000 -------
sparc, how's your happiness factor? :)

------- Comment #11 From Gustavo Zacarias (RETIRED) 2006-08-02 10:38:14 0000 -------
sparc stable.

------- Comment #12 From Raphael Marichez 2006-08-03 01:05:14 0000 -------
see CVE 3389 & 3390 : i vote a full NO.

------- Comment #13 From Harlan Lieberman-Berg (RETIRED) 2006-08-03 01:08:55 0000 -------
I vote a big no.

------- Comment #14 From Wolf Giesen (RETIRED) 2006-08-03 01:18:19 0000 -------
NO

------- Comment #15 From Sune Kloppenborg Jeppesen 2006-08-03 01:25:24 0000 -------
Might also fix another issue, but I can't really find any information on it
justifying a GLSA.

So I guess this is a NO as well.

------- Comment #16 From Wolf Giesen (RETIRED) 2006-08-03 02:10:07 0000 -------
http://unknowngenius.com/blog/archives/2006/07/27/followup-on-wordpress/
produces a lot of FUD, there's a follow-up that *might* make us want to
reconsider:

http://www.4null4.de/174/wp-users-disable-guest-account-registration-immediately/

------- Comment #17 From Sune Kloppenborg Jeppesen 2006-08-03 02:15:35 0000 -------
@comment #15: Not really a lot of information there either. Maybe we should try
mailing upstream?

------- Comment #18 From Wolf Giesen (RETIRED) 2006-08-03 02:22:46 0000 -------
I'll try but I doubt the usefulness .-)

------- Comment #19 From Wolf Giesen (RETIRED) 2006-08-03 02:29:59 0000 -------
Wordpress contacted.

------- Comment #20 From Wolf Giesen (RETIRED) 2006-08-03 23:53:50 0000 -------
Ok, I got an answer from WordPress; there is a problem in the core application
not mentioned here yet that they wish not yet published. Details available from
me. I personally think might want to issue a GLSA. After all, WP *is* in the
official tree, so we can't really bail out on our own commitment.

------- Comment #21 From Wolf Giesen (RETIRED) 2006-08-07 04:44:28 0000 -------
Pinging SecTeam again

------- Comment #22 From Raphael Marichez 2006-08-07 05:27:15 0000 -------
(In reply to comment #20)
> Pinging SecTeam again
> 

i vote no glsa

------- Comment #23 From Wolf Giesen (RETIRED) 2006-08-07 05:27:52 0000 -------
I change to YES.

------- Comment #24 From Matthias Geerdsen 2006-08-07 05:59:28 0000 -------
/me tends to vote yes

------- Comment #25 From Sune Kloppenborg Jeppesen 2006-08-07 09:38:21 0000 -------
Ok, lets have a GLSA with no details :-)

------- Comment #26 From Stefan Cornelius (RETIRED) 2006-08-07 09:39:27 0000 -------
I dont get this. I probably misunderstand the whole thing... So what we have
is: the 2 CVEs. One absolutely minor, and one disputed and minor -> no glsa.

Then we have some FUD coming from blogs. Uh yeah, blogs ...no real info
there,too. I wont issue a GLSA, saying "XY said on his blog that one might be
able to conduct $evilthings" -> no glsa.

Then we have that other unknown problem. Is that fixed in 2.0.4? Is this
related to 3rd party plugins? If a users installs 3rd party plugs, then it's
his own problem. -> no glsa.

------- Comment #27 From Wolf Giesen (RETIRED) 2006-08-07 09:55:20 0000 -------
Frankly I don't give a damn. If you ask me, mask the app. My point still stands
that the bug is in the core. Installing plugins is your own risk, the core not
handling plugins correctly is not. Just close if you see fit.

------- Comment #28 From Sune Kloppenborg Jeppesen 2006-08-07 12:39:26 0000 -------
@comment #25: the so called FUD and unknown problem appears to be one and the
same thing.

@comment #26: User roles and capabilities are clearly described by upstream:
http://codex.wordpress.org/Roles_and_Capabilities

If my understanding of the issue is correct I'd rerate as C1.

------- Comment #29 From Wolf Giesen (RETIRED) 2006-08-07 12:49:40 0000 -------
Thanks and excuse my outburst .-)

------- Comment #30 From Wolf Giesen (RETIRED) 2006-08-08 05:13:10 0000 -------
Rerating to C1 after discussion, even if it's only to be on the safe side.
Ready for GLSA, then.

------- Comment #31 From Raphael Marichez 2006-08-10 14:04:21 0000 -------
GLSA 200608-19

thanks to all

------- Comment #32 From Wolf Giesen (RETIRED) 2006-08-11 06:58:02 0000 -------
Thanks, and fight the FUD :P

Bug List: (This bug is not in your last search results)   Show last search results      Search page      Enter new bug