Bug#862816: wordpress: Six security bugs in wordpress 4.7.4 and earlier

2017-05-17 Thread Rodrigo Campos
On Wed, May 17, 2017 at 09:54:55PM +1000, Craig Small wrote: > Source: wordpress > Version: 4.7.4+dfsg-1 > Severity: grave > Tags: upstream security > Justification: user security hole > > Wordpress 4.7.4 and earlier has 6 security holes that are fixed in > 4.7.5[1] > > * 2.7.0 - 4.7.4 >Insu

Bug#862816: wordpress: Six security bugs in wordpress 4.7.4 and earlier

2017-05-17 Thread Craig Small
Source: wordpress Version: 4.7.4+dfsg-1 Severity: grave Tags: upstream security Justification: user security hole Wordpress 4.7.4 and earlier has 6 security holes that are fixed in 4.7.5[1] * 2.7.0 - 4.7.4 Insufficient redirect validation in the HTTP class. * 2.5.0 - 4.7.4 Improper handli