Gentoo Websites Logo
Go to: Gentoo Home Documentation Forums Lists Bugs Planet Store Wiki Get Gentoo!
Bug 348610 - <www-apps/wordpress-3.0.3: privilege escalation in XML-RPC remote publishing interface (CVE-2010-5106)
Summary: <www-apps/wordpress-3.0.3: privilege escalation in XML-RPC remote publishing ...
Status: RESOLVED FIXED
Alias: None
Product: Gentoo Security
Classification: Unclassified
Component: Vulnerabilities (show other bugs)
Hardware: All All
: High normal (vote)
Assignee: Gentoo Security
URL: http://codex.wordpress.org/Version_3.0.3
Whiteboard: ~4 [noglsa]
Keywords:
Depends on:
Blocks:
 
Reported: 2010-12-13 12:45 UTC by kfm
Modified: 2012-09-16 13:55 UTC (History)
2 users (show)

See Also:
Package list:
Runtime testing required: ---


Attachments

Note You need to log in before you can comment on or make changes to this bug.
Description kfm 2010-12-13 12:45:04 UTC
From the URL:

"Fixes issues in the XML-RPC remote publishing interface which under certain circumstances allowed Author- and Contributor-level users to improperly edit, publish or delete posts. (r16803)"

As it's fixed in 3.0.3, I would suggest a fast-track stabilisation process and the subsequent removal of both 3.0.1 and 3.0.2.
Comment 1 Theo Chatzimichos (RETIRED) archtester gentoo-dev Security 2010-12-13 13:00:04 UTC
the wordpress 3.0.3 is in tree already. As blogs.g.o is using it, we try to bump it immediatelly. There is no stable version of wordpress though, and I don't think there is any reason to stabilize it.
Comment 2 kfm 2010-12-13 13:28:22 UTC
OK. Maybe just drop 3.0.1 and 3.0.2 then? I'm not sure how many out there actually use the XML-RPC interface but it seems nasty enough to take that extra step to ensure that no-one (unwittingly) uses a vulnerable version.
Comment 3 kfm 2010-12-13 13:30:26 UTC
Also, if you're looking for a quick production fix for blogs.gentoo.org, here's the diff:

http://core.trac.wordpress.org/changeset/16803?format=diff&new=16803
Comment 4 Theo Chatzimichos (RETIRED) archtester gentoo-dev Security 2010-12-13 13:49:25 UTC
I was aware of those diffs, they are included in the announcement pages, but thanks anyway.
wordpress 3.0.{1,2} removed from tree
Comment 5 Tim Sammut (RETIRED) gentoo-dev 2010-12-13 14:13:55 UTC
Thanks, folks. Closing noglsa.
Comment 6 GLSAMaker/CVETool Bot gentoo-dev 2012-09-16 13:55:45 UTC
CVE-2010-5106 (http://nvd.nist.gov/nvd.cfm?cvename=CVE-2010-5106):
  The XML-RPC remote publishing interface in xmlrpc.php in WordPress before
  3.0.3 does not properly check capabilities, which allows remote
  authenticated users to bypass intended access restrictions, and publish,
  edit, or delete posts, by leveraging the Author or Contributor role.