[<prev] [next>] [thread-next>] [month] [year] [list]
Date: Tue, 19 Aug 2008 11:33:46 +0200
From: Hanno Böck <hanno@...eck.de>
To: oss-security@...ts.openwall.com
Cc: coley@...re.org
Subject: wordpress 2.6.1
Just had a look at the wp 2.6.1 changelog.
Two security relevant bugs are listed as fixed.
http://trac.wordpress.org/ticket/7359
I'd consider this worth a CVE. It's good that this ssl stuff got some
attention lately (I think this is a similar issue to the recently reported
cookie / secureflag issues, as it can undermine the sniffing-safety of
ssl-enabled pages).
http://trac.wordpress.org/ticket/6871
AFAICS this enables one to hide malicious plugins but is no real vuln. Not
sure if it deserves a CVE.
--
Hanno Böck Blog: http://www.hboeck.de/
GPG: 3DBD3B20 Jabber/Mail: hanno@...eck.de
[ CONTENT OF TYPE application/pgp-signature SKIPPED ]
Please check out the
Open Source Software Security Wiki, which is counterpart to this
mailing list.
Hosted by DataForce ISP -
Powered by Openwall GNU/*/Linux