Gentoo Websites Logo
Go to: Gentoo Home Documentation Forums Lists Bugs Planet Store Wiki Get Gentoo!
Bug 634702 (CVE-2017-9061, CVE-2017-9062, CVE-2017-9063, CVE-2017-9064, CVE-2017-9065, CVE-2017-9066) - www-apps/wordpress: Multiple vulnerabilities
Summary: www-apps/wordpress: Multiple vulnerabilities
Status: RESOLVED INVALID
Alias: CVE-2017-9061, CVE-2017-9062, CVE-2017-9063, CVE-2017-9064, CVE-2017-9065, CVE-2017-9066
Product: Gentoo Security
Classification: Unclassified
Component: Vulnerabilities (show other bugs)
Hardware: All Linux
: Normal trivial (vote)
Assignee: Gentoo Security
URL:
Whiteboard: ~4 [noglsa cve]
Keywords:
Depends on:
Blocks:
 
Reported: 2017-10-19 00:51 UTC by GLSAMaker/CVETool Bot
Modified: 2017-10-20 01:32 UTC (History)
1 user (show)

See Also:
Package list:
Runtime testing required: ---


Attachments

Note You need to log in before you can comment on or make changes to this bug.
Description GLSAMaker/CVETool Bot gentoo-dev 2017-10-19 00:51:58 UTC
CVE-2017-9066 (http://nvd.nist.gov/nvd.cfm?cvename=CVE-2017-9066):
  In WordPress before 4.7.5, there is insufficient redirect validation in the
  HTTP class, leading to SSRF.

CVE-2017-9065 (http://nvd.nist.gov/nvd.cfm?cvename=CVE-2017-9065):
  In WordPress before 4.7.5, there is a lack of capability checks for post
  meta data in the XML-RPC API.

CVE-2017-9064 (http://nvd.nist.gov/nvd.cfm?cvename=CVE-2017-9064):
  In WordPress before 4.7.5, a Cross Site Request Forgery (CSRF) vulnerability
  exists in the filesystem credentials dialog because a nonce is not required
  for updating credentials.

CVE-2017-9063 (http://nvd.nist.gov/nvd.cfm?cvename=CVE-2017-9063):
  In WordPress before 4.7.5, a cross-site scripting (XSS) vulnerability
  related to the Customizer exists, involving an invalid customization
  session.

CVE-2017-9062 (http://nvd.nist.gov/nvd.cfm?cvename=CVE-2017-9062):
  In WordPress before 4.7.5, there is improper handling of post meta data
  values in the XML-RPC API.

CVE-2017-9061 (http://nvd.nist.gov/nvd.cfm?cvename=CVE-2017-9061):
  In WordPress before 4.7.5, a cross-site scripting (XSS) vulnerability exists
  when attempting to upload very large files, because the error message does
  not properly restrict presentation of the filename.
Comment 1 Anthony Basile gentoo-dev 2017-10-19 13:51:30 UTC
The oldest version in the tree is 4.7.5 which, if I'm reading the reports correctly, is not vulnerable.
Comment 2 Christopher Díaz Riveros (RETIRED) gentoo-dev Security 2017-10-19 15:59:11 UTC
Thanks for the confirmation Anthony I'm closing the report since we have nothing else to do here.

GLSA Vote: No