Bug 142142 - www-apps/wordpress - security version bump to 2.0.4 (CVE-2006-3389|3390)
Bug#: 142142 Product:  Gentoo Security Version: unspecified Platform: All
OS/Version: Other Status: CLOSED Severity: normal Priority: P2
Resolution: FIXED Assigned To: security@gentoo.org Reported By: superlag@gentoo.org
Component: Vulnerabilities
URL:  http://wordpress.org/development/2006/07/wordpress-204/
Summary: www-apps/wordpress - security version bump to 2.0.4 (CVE-2006-3389|3390)
Keywords:  
Status Whiteboard: C1 [glsa] frilled
Opened: 2006-07-29 19:45 0000
Description:   Opened: 2006-07-29 19:45 0000
Version 2.0.4 fixes some bugs.  Bump.

------- Comment #1 From Aaron Kulbe (RETIRED) 2006-07-29 19:49:05 0000 -------
Done.

------- Comment #2 From Aaron Kulbe (RETIRED) 2006-07-30 17:09:34 0000 -------
An ebuild name would help....


www-apps/wordpress

bumped from 2.0.3 to 2.0.4

------- Comment #3 From Matthias Geerdsen 2006-07-31 05:38:54 0000 -------
taking over the bug since 2.0.4 fixes security issues

"WordPress 2.0.4, the latest stable release in our Duke series, is available
for immediate download. This release contains several important security fixes,
so it

------- Comment #4 From Matthias Geerdsen 2006-07-31 05:38:54 0000 -------
taking over the bug since 2.0.4 fixes security issues

"WordPress 2.0.4, the latest stable release in our Duke series, is available
for immediate download. This release contains several important security fixes,
so it’s highly recommended for all users. We’ve also rolled in a number of
bug fixes (over 50!), so it’s a pretty solid release across the board."

arches, please test and mark wordpress-2.0.4 stable if possible

------- Comment #5 From Wolf Giesen (RETIRED) 2006-07-31 05:49:27 0000 -------
2.0.3 is affected by
http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2006-3390 and
http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2006-3389

Which sounds like B3/minor to me.

------- Comment #6 From Matthias Geerdsen 2006-07-31 05:51:32 0000 -------
oh and there is this... "announcement"

http://unknowngenius.com/blog/archives/2006/07/26/critical-announcement-to-all-wordpress-users/

------- Comment #7 From René Nussbaumer 2006-07-31 10:12:20 0000 -------
stable on hppa

------- Comment #8 From Tobias Scherbaum 2006-07-31 11:00:57 0000 -------
ppc stable

------- Comment #9 From Joshua Jackson 2006-07-31 20:11:32 0000 -------
x86 is gone ^.^

------- Comment #10 From Wolf Giesen (RETIRED) 2006-08-02 02:09:04 0000 -------
sparc, how's your happiness factor? :)

------- Comment #11 From Gustavo Zacarias (RETIRED) 2006-08-02 10:38:14 0000 -------
sparc stable.

------- Comment #12 From Raphael Marichez 2006-08-03 01:05:14 0000 -------
see CVE 3389 & 3390 : i vote a full NO.

------- Comment #13 From Harlan Lieberman-Berg (RETIRED) 2006-08-03 01:08:55 0000 -------
I vote a big no.

------- Comment #14 From Wolf Giesen (RETIRED) 2006-08-03 01:18:19 0000 -------
NO

------- Comment #15 From Sune Kloppenborg Jeppesen 2006-08-03 01:25:24 0000 -------
Might also fix another issue, but I can't really find any information on it
justifying a GLSA.

So I guess this is a NO as well.

------- Comment #16 From Wolf Giesen (RETIRED) 2006-08-03 02:10:07 0000 -------
http://unknowngenius.com/blog/archives/2006/07/27/followup-on-wordpress/
produces a lot of FUD, there's a follow-up that *might* make us want to
reconsider:

http://www.4null4.de/174/wp-users-disable-guest-account-registration-immediately/

------- Comment #17 From Sune Kloppenborg Jeppesen 2006-08-03 02:15:35 0000 -------
@comment #15: Not really a lot of information there either. Maybe we should try
mailing upstream?

------- Comment #18 From Wolf Giesen (RETIRED) 2006-08-03 02:22:46 0000 -------
I'll try but I doubt the usefulness .-)

------- Comment #19 From Wolf Giesen (RETIRED) 2006-08-03 02:29:59 0000 -------
Wordpress contacted.

------- Comment #20 From Wolf Giesen (RETIRED) 2006-08-03 23:53:50 0000 -------
Ok, I got an answer from WordPress; there is a problem in the core application
not mentioned here yet that they wish not yet published. Details available from
me. I personally think might want to issue a GLSA. After all, WP *is* in the
official tree, so we can't really bail out on our own commitment.

------- Comment #21 From Wolf Giesen (RETIRED) 2006-08-07 04:44:28 0000 -------
Pinging SecTeam again

------- Comment #22 From Raphael Marichez 2006-08-07 05:27:15 0000 -------
(In reply to comment #20)
> Pinging SecTeam again
> 

i vote no glsa

------- Comment #23 From Wolf Giesen (RETIRED) 2006-08-07 05:27:52 0000 -------
I change to YES.

------- Comment #24 From Matthias Geerdsen 2006-08-07 05:59:28 0000 -------
/me tends to vote yes

------- Comment #25 From Sune Kloppenborg Jeppesen 2006-08-07 09:38:21 0000 -------
Ok, lets have a GLSA with no details :-)

------- Comment #26 From Stefan Cornelius (RETIRED) 2006-08-07 09:39:27 0000 -------
I dont get this. I probably misunderstand the whole thing... So what we have
is: the 2 CVEs. One absolutely minor, and one disputed and minor -> no glsa.

Then we have some FUD coming from blogs. Uh yeah, blogs ...no real info
there,too. I wont issue a GLSA, saying "XY said on his blog that one might be
able to conduct $evilthings" -> no glsa.

Then we have that other unknown problem. Is that fixed in 2.0.4? Is this
related to 3rd party plugins? If a users installs 3rd party plugs, then it's
his own problem. -> no glsa.

------- Comment #27 From Wolf Giesen (RETIRED) 2006-08-07 09:55:20 0000 -------
Frankly I don't give a damn. If you ask me, mask the app. My point still stands
that the bug is in the core. Installing plugins is your own risk, the core not
handling plugins correctly is not. Just close if you see fit.

------- Comment #28 From Sune Kloppenborg Jeppesen 2006-08-07 12:39:26 0000 -------
@comment #25: the so called FUD and unknown problem appears to be one and the
same thing.

@comment #26: User roles and capabilities are clearly described by upstream:
http://codex.wordpress.org/Roles_and_Capabilities

If my understanding of the issue is correct I'd rerate as C1.

------- Comment #29 From Wolf Giesen (RETIRED) 2006-08-07 12:49:40 0000 -------
Thanks and excuse my outburst .-)

------- Comment #30 From Wolf Giesen (RETIRED) 2006-08-08 05:13:10 0000 -------
Rerating to C1 after discussion, even if it's only to be on the safe side.
Ready for GLSA, then.

------- Comment #31 From Raphael Marichez 2006-08-10 14:04:21 0000 -------
GLSA 200608-19

thanks to all

------- Comment #32 From Wolf Giesen (RETIRED) 2006-08-11 06:58:02 0000 -------
Thanks, and fight the FUD :P