Gentoo Websites Logo
Go to: Gentoo Home Documentation Forums Lists Bugs Planet Store Wiki Get Gentoo!
Bug 290013 - <www-apps/wordpress-2.8.5: Hardening Release (CVE-2009-3622)
Summary: <www-apps/wordpress-2.8.5: Hardening Release (CVE-2009-3622)
Status: RESOLVED FIXED
Alias: None
Product: Gentoo Security
Classification: Unclassified
Component: Vulnerabilities (show other bugs)
Hardware: All Linux
: High trivial (vote)
Assignee: Gentoo Security
URL: http://wordpress.org/development/2009...
Whiteboard: ~2 [noglsa]
Keywords:
Depends on:
Blocks:
 
Reported: 2009-10-21 13:49 UTC by Bernd Marienfeldt
Modified: 2009-10-25 15:18 UTC (History)
3 users (show)

See Also:
Package list:
Runtime testing required: ---


Attachments

Note You need to log in before you can comment on or make changes to this bug.
Description Bernd Marienfeldt 2009-10-21 13:49:07 UTC
The headline changes in this release are:

 * A fix for the Trackback Denial-of-Service attack that is currently being seen.
 * Removal of areas within the code where php code in variables was evaluated.
 * Switched the file upload functionality to be whitelisted for all users including Admins.
 * Retiring of the two importers of Tag data from old plugins.
Comment 1 Tobias Scherbaum (RETIRED) gentoo-dev 2009-10-21 19:45:21 UTC
2.8.5 in CVS.
Comment 2 Alex Legler (RETIRED) archtester gentoo-dev Security 2009-10-21 20:15:58 UTC
Not stable -> Closing noglsa. Thanks.
Comment 3 Alex Legler (RETIRED) archtester gentoo-dev Security 2009-10-25 15:18:23 UTC
CVE-2009-3622 (http://nvd.nist.gov/nvd.cfm?cvename=CVE-2009-3622):
  Algorithmic complexity vulnerability in wp-trackback.php in WordPress
  before 2.8.5 allows remote attackers to cause a denial of service
  (CPU consumption and server hang) via a long title parameter in
  conjunction with a charset parameter composed of many comma-separated
  "UTF-8" substrings, related to the mb_convert_encoding function in
  PHP.