Your message dated Sat, 26 Apr 2008 21:02:24 +0000
with message-id <[EMAIL PROTECTED]>
and subject line Bug#477910: fixed in wordpress 2.5.1-1
has caused the Debian Bug report #477910,
regarding wordpress: CVE-2008-1930 integrity protection vulnerability
to be marked as done.
This means that you claim that the problem has been dealt with.
If this is not the case it is now your responsibility to reopen the
Bug report if necessary, and/or fix the problem forthwith.
(NB: If you are a system administrator and have no idea what this
message is talking about, this may indicate a serious mail system
misconfiguration somewhere. Please contact [EMAIL PROTECTED]
immediately.)
--
477910: http://bugs.debian.org/cgi-bin/bugreport.cgi?bug=477910
Debian Bug Tracking System
Contact [EMAIL PROTECTED] with problems
--- Begin Message ---
Package: wordpress
Severity: grave
Tags: security
Hi,
the following CVE (Common Vulnerabilities & Exposures) id was
published for wordpress.
CVE-2008-1930[0]:
| An attacker, who is able to register a specially crafted username on
| a Wordpress 2.5 installation, is able to generate authentication
| cookies for other chosen accounts.
|
| This vulnerability exists because it is possible to modify
| authentication cookies without invalidating the cryptographic
| integrity protection.
|
| If a Wordpress blog is configured to freely permit account creation,
| a remote attacker can gain Wordpress-administrator access and then
| elevate this to arbitrary code execution as the web server user.
Note, this is not yet on the mitre site, see:
http://wordpress.org/development/2008/04/wordpress-251/ in the meantime.
If you fix the vulnerability please also make sure to include the
CVE id in your changelog entry.
For further information see:
[0] http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2008-1930
http://security-tracker.debian.net/tracker/CVE-2008-1930
--
Nico Golde - http://www.ngolde.de - [EMAIL PROTECTED] - GPG: 0x73647CFF
For security reasons, all text in this mail is double-rot13 encrypted.
pgpB6rTuT5aqP.pgp
Description: PGP signature
--- End Message ---
--- Begin Message ---
Source: wordpress
Source-Version: 2.5.1-1
We believe that the bug you reported is fixed in the latest version of
wordpress, which is due to be installed in the Debian FTP archive:
wordpress_2.5.1-1.diff.gz
to pool/main/w/wordpress/wordpress_2.5.1-1.diff.gz
wordpress_2.5.1-1.dsc
to pool/main/w/wordpress/wordpress_2.5.1-1.dsc
wordpress_2.5.1-1_all.deb
to pool/main/w/wordpress/wordpress_2.5.1-1_all.deb
wordpress_2.5.1.orig.tar.gz
to pool/main/w/wordpress/wordpress_2.5.1.orig.tar.gz
A summary of the changes between this version and the previous one is
attached.
Thank you for reporting the bug, which will now be closed. If you
have further comments please address them to [EMAIL PROTECTED],
and the maintainer will reopen the bug report if appropriate.
Debian distribution maintenance software
pp.
Andrea De Iacovo <[EMAIL PROTECTED]> (supplier of updated wordpress package)
(This message was generated automatically at their request; if you
believe that there is a problem with it please contact the archive
administrators by mailing [EMAIL PROTECTED])
-----BEGIN PGP SIGNED MESSAGE-----
Hash: SHA1
Format: 1.8
Date: Sat, 26 Apr 2008 19:08:14 +0200
Source: wordpress
Binary: wordpress
Architecture: source all
Version: 2.5.1-1
Distribution: unstable
Urgency: high
Maintainer: Andrea De Iacovo <[EMAIL PROTECTED]>
Changed-By: Andrea De Iacovo <[EMAIL PROTECTED]>
Description:
wordpress - weblog manager
Closes: 477910
Changes:
wordpress (2.5.1-1) unstable; urgency=high
.
* Merged with upstream 2.5.1 security release
* CVE-2008-1930 integrity protection vulnerability (Closes: #477910)
* Depends on tinymce
Checksums-Sha1:
e212afdf9d5eea32450d26dd8da1adebb88a8d7a 1018 wordpress_2.5.1-1.dsc
4a8d82e9a80bc5b5c1c251e00296e93dbb364829 1181886 wordpress_2.5.1.orig.tar.gz
4772525f0453907d7d6d720f0abbf3a9c133b964 749858 wordpress_2.5.1-1.diff.gz
519cfa543d94610166e4a129e679108dde5b4248 1064914 wordpress_2.5.1-1_all.deb
Checksums-Sha256:
c888908af2858477b9ab9918f3c162edb3f793136b9986ca5bbc8646bcb8ab8a 1018
wordpress_2.5.1-1.dsc
3ac5b9287d61ff90f9e1f5790dcfeda490b2da21b5af9098b2f76c3e8059057b 1181886
wordpress_2.5.1.orig.tar.gz
0f02a5376b422e6c3783f3443facd8eddf9e31fe547e83842807787847ed8f36 749858
wordpress_2.5.1-1.diff.gz
d535e10fa405d5970061f09e88982bdedd4c179b4b57992128b14eb57cc9626f 1064914
wordpress_2.5.1-1_all.deb
Files:
e900cb4353b786b1f60dedd3ce293cfe 1018 web optional wordpress_2.5.1-1.dsc
b1a40387006e54dcbd963d0cb5da0df4 1181886 web optional
wordpress_2.5.1.orig.tar.gz
1f712d682234bb336942f919f421dbe4 749858 web optional wordpress_2.5.1-1.diff.gz
0ae81179574cef399edba0f3da341668 1064914 web optional wordpress_2.5.1-1_all.deb
-----BEGIN PGP SIGNATURE-----
Version: GnuPG v1.4.6 (GNU/Linux)
iD8DBQFIE4mfHYflSXNkfP8RArCaAJwM2VhT/4na16qfqc4xowFmKoAa5gCeJIL0
qDyu2T+5gpaTOmwqjjt0HnI=
=fpYv
-----END PGP SIGNATURE-----
--- End Message ---