Gentoo Websites Logo
Go to: Gentoo Home Documentation Forums Lists Bugs Planet Store Wiki Get Gentoo!
Bug 634832 (CVE-2012-6707) - <www-apps/wordpress-4.8.2: Information Leak (CVE-2012-6707)
Summary: <www-apps/wordpress-4.8.2: Information Leak (CVE-2012-6707)
Status: RESOLVED FIXED
Alias: CVE-2012-6707
Product: Gentoo Security
Classification: Unclassified
Component: Vulnerabilities (show other bugs)
Hardware: All Linux
: Low trivial (vote)
Assignee: Gentoo Security
URL: https://core.trac.wordpress.org/ticke...
Whiteboard: ~4 [noglsa cve]
Keywords:
Depends on:
Blocks:
 
Reported: 2017-10-19 23:10 UTC by D'juan McDonald (domhnall)
Modified: 2017-11-27 17:46 UTC (History)
1 user (show)

See Also:
Package list:
Runtime testing required: ---


Attachments

Note You need to log in before you can comment on or make changes to this bug.
Description D'juan McDonald (domhnall) 2017-10-19 23:10:23 UTC
CVE-2012-6707 (https://web.nvd.nist.gov/view/vuln/detail?vulnId=CVE-2012-6707):

WordPress through 4.8.2 uses a weak MD5-based password hashing algorithm, which makes it easier for attackers to determine cleartext values by leveraging access to the hash values. NOTE: the approach to changing this may not be fully compatible with certain use cases, such as migration of a WordPress site from a web host that uses a recent PHP version to a different web host that uses PHP 5.2. These use cases are plausible (but very unlikely) based on statistics showing widespread deployment of WordPress with obsolete PHP versions.


@maintainer(s), in case of bump, please call for stabilization, thank you.

Gentoo Security Padawan
Daj Uan (jmbailey)
Comment 1 Anthony Basile gentoo-dev 2017-11-27 14:37:16 UTC
I've removed all <= 4.8.2.  No stabilization needed.
Comment 2 Christopher Díaz Riveros (RETIRED) gentoo-dev Security 2017-11-27 16:07:06 UTC
      |                                 |   u       |  
      | a a         p   a     n r     s |   n       |  
      | l m   h i   p   r m m i i s   p | e u s     | r
      | p d a p a p c x m i 6 o s 3   a | a s l     | e
      | h 6 r p 6 p 6 8 6 p 8 s c 9 s r | p e o     | p
      | a 4 m a 4 c 4 6 4 s k 2 v 0 h c | i d t     | o
------+---------------------------------+-----------+-------
  4.8 | o ~ ~ ~ o ~ ~ ~ o o o o o o o ~ | 6 o 4.8   | gentoo

still in tree, maybe a commit?

Thanks
Comment 3 Anthony Basile gentoo-dev 2017-11-27 16:22:47 UTC
(In reply to Christopher Díaz Riveros from comment #2)
>       |                                 |   u       |  
>       | a a         p   a     n r     s |   n       |  
>       | l m   h i   p   r m m i i s   p | e u s     | r
>       | p d a p a p c x m i 6 o s 3   a | a s l     | e
>       | h 6 r p 6 p 6 8 6 p 8 s c 9 s r | p e o     | p
>       | a 4 m a 4 c 4 6 4 s k 2 v 0 h c | i d t     | o
> ------+---------------------------------+-----------+-------
>   4.8 | o ~ ~ ~ o ~ ~ ~ o o o o o o o ~ | 6 o 4.8   | gentoo
> 
> still in tree, maybe a commit?
> 
> Thanks

sorry i messed that one.  it should be fixed now.