Gentoo Websites Logo
Go to: Gentoo Home Documentation Forums Lists Bugs Planet Store Wiki Get Gentoo!
Bug 519246 - <www-apps/wordpress-3.9.2: Denial of Service (CVE-2014-{5203,5204,5205,5240})
Summary: <www-apps/wordpress-3.9.2: Denial of Service (CVE-2014-{5203,5204,5205,5240})
Status: RESOLVED FIXED
Alias: None
Product: Gentoo Security
Classification: Unclassified
Component: Vulnerabilities (show other bugs)
Hardware: All Linux
: Normal trivial (vote)
Assignee: Gentoo Security
URL: https://wordpress.org/news/2014/08/wo...
Whiteboard: ~3 [noglsa]
Keywords:
Depends on:
Blocks:
 
Reported: 2014-08-06 19:57 UTC by Kristian Fiskerstrand (RETIRED)
Modified: 2015-01-10 16:52 UTC (History)
1 user (show)

See Also:
Package list:
Runtime testing required: ---


Attachments

Note You need to log in before you can comment on or make changes to this bug.
Description Kristian Fiskerstrand (RETIRED) gentoo-dev 2014-08-06 19:57:37 UTC
From ${URL}:
WordPress 3.9.2 is now available as a security release for all previous versions. We strongly encourage you to update your sites immediately.

This release fixes a possible denial of service issue in PHP’s XML processing, reported by Nir Goldshlager of the Salesforce.com Product Security Team. It  was fixed by Michael Adams and Andrew Nacin of the WordPress security team and David Rothstein of the Drupal security team. This is the first time our two projects have coordinated on joint security releases.

WordPress 3.9.2 also contains other security changes
Comment 1 Yury German Gentoo Infrastructure gentoo-dev 2014-08-17 04:17:12 UTC
Maintainer(s), please drop the vulnerable version(s).
Comment 2 Mikle Kolyada (RETIRED) archtester Gentoo Infrastructure gentoo-dev Security 2014-12-28 22:30:47 UTC
Cleanup was done. There is only 3.9.3 in 3.9.x branch
Comment 3 GLSAMaker/CVETool Bot gentoo-dev 2015-01-10 16:52:38 UTC
CVE-2014-5240 (http://nvd.nist.gov/nvd.cfm?cvename=CVE-2014-5240):
  Cross-site scripting (XSS) vulnerability in wp-includes/pluggable.php in
  WordPress before 3.9.2, when Multisite is enabled, allows remote
  authenticated administrators to inject arbitrary web script or HTML, and
  obtain Super Admin privileges, via a crafted avatar URL.

CVE-2014-5205 (http://nvd.nist.gov/nvd.cfm?cvename=CVE-2014-5205):
  wp-includes/pluggable.php in WordPress before 3.9.2 does not use delimiters
  during concatenation of action values and uid values in CSRF tokens, which
  makes it easier for remote attackers to bypass a CSRF protection mechanism
  via a brute-force attack.

CVE-2014-5204 (http://nvd.nist.gov/nvd.cfm?cvename=CVE-2014-5204):
  wp-includes/pluggable.php in WordPress before 3.9.2 rejects invalid CSRF
  nonces with a different timing depending on which characters in the nonce
  are incorrect, which makes it easier for remote attackers to bypass a CSRF
  protection mechanism via a brute-force attack.

CVE-2014-5203 (http://nvd.nist.gov/nvd.cfm?cvename=CVE-2014-5203):
  wp-includes/class-wp-customize-widgets.php in the widget implementation in
  WordPress 3.9.x before 3.9.2 might allow remote attackers to execute
  arbitrary code via crafted serialized data.