Gentoo Websites Logo
Go to: Gentoo Home Documentation Forums Lists Bugs Planet Store Wiki Get Gentoo!
Bug 548828 - <www-apps/wordpress-4.2.3: two cross-site scripting (CVE-2015-{5622,5623})
Summary: <www-apps/wordpress-4.2.3: two cross-site scripting (CVE-2015-{5622,5623})
Status: RESOLVED FIXED
Alias: None
Product: Gentoo Security
Classification: Unclassified
Component: Vulnerabilities (show other bugs)
Hardware: All Linux
: Normal trivial (vote)
Assignee: Gentoo Security
URL: https://bugzilla.redhat.com/show_bug....
Whiteboard: ~4 [noglsa cve]
Keywords:
Depends on:
Blocks:
 
Reported: 2015-05-07 09:22 UTC by Agostino Sarubbo
Modified: 2015-08-15 14:13 UTC (History)
2 users (show)

See Also:
Package list:
Runtime testing required: ---


Attachments

Note You need to log in before you can comment on or make changes to this bug.
Description Agostino Sarubbo gentoo-dev 2015-05-07 09:22:19 UTC
From ${URL} :

wo cross-site scripting flaws were found in WordPress:

* The Genericons icon font package, which is used in a number of popular themes and plugins, contained an HTML file vulnerable to a cross-site scripting attack.

* WordPress versions 4.2 and earlier are affected by a critical cross-site scripting vulnerability, which could enable anonymous users to compromise a site.

Both of these issues have been fixed in the 4.2.2 release of WordPress.

Upstream advisory:

https://wordpress.org/news/2015/05/wordpress-4-2-2/


@maintainer(s): since the package or the affected version has never been marked as stable, we don't need to stabilize it. After the bump, please remove the affected versions from the tree.
Comment 1 Leho Kraav (:macmaN @lkraav) 2015-07-23 12:21:22 UTC
In light of https://wordpress.org/news/2015/07/wordpress-4-2-3/, 4.2.2 also has XSS vulnerabilities and should be immediately dropped in favor of 4.2.3.
Comment 2 Jorge Manuel B. S. Vicetto (RETIRED) Gentoo Infrastructure gentoo-dev 2015-07-25 02:36:09 UTC
02:33 < gentoovcs> jmbsvicetto → gentoo-x86 (www-apps/wordpress/) Bump wordpress to release 4.2.3 - fixes bug 548828. Security bump to address CVE-2015-5622 and CVE-2015-5623.

Ebuild added to the tree.
Comment 3 Sebastian Pipping gentoo-dev 2015-07-25 16:34:27 UTC
+  25 Jul 2015; Sebastian Pipping <sping@gentoo.org> -wordpress-3.8.5.ebuild,
+  -wordpress-3.9.3.ebuild, -wordpress-4.0.1.ebuild, -wordpress-4.1.ebuild,
+  -wordpress-4.1.1.ebuild, -wordpress-4.1.2-r2.ebuild, -wordpress-4.2.ebuild,
+  -wordpress-4.2.1.ebuild, -wordpress-4.2.2.ebuild:
+  Remove vulnerable releases (bug #548828 but not only)
+
Comment 4 Yury German Gentoo Infrastructure gentoo-dev 2015-08-15 14:10:43 UTC
Maintainer(s), Thank you for you for your work.
No stable versions, closing as noglsa.
Comment 5 Leho Kraav (:macmaN @lkraav) 2015-08-15 14:13:34 UTC
Actually, removing all older versions was overshooting it a bit. WP is supported at upstream 4 releases back. So currently 3.8-branch still receives all upgrades and would be valid for living in our precious tree as well.

Now the amount of work associated with this is another matter. I'm mainly looking to clarify here whether the package maintainer knows about the upstream policy or not.