Debian DSA-3375-1 : wordpress - security update

medium Nessus Plugin ID 86448

Synopsis

The remote Debian host is missing a security-related update.

Description

Several vulnerabilities have been fixed in Wordpress, the popular blogging engine.

- CVE-2015-5714 A cross-site scripting vulnerability when processing shortcode tags has been discovered.

The issue has been fixed by not allowing unclosed HTML elements in attributes.

- CVE-2015-5715 A vulnerability has been discovered, allowing users without proper permissions to publish private posts and make them sticky.

The issue has been fixed in the XMLRPC code of Wordpress by not allowing private posts to be sticky.

- CVE-2015-7989 A cross-site scripting vulnerability in user list tables has been discovered.

The issue has been fixed by URL-escaping email addresses in those user lists.

Solution

Upgrade the wordpress packages.

For the oldstable distribution (wheezy), these problems will be fixed in later update.

For the stable distribution (jessie), these problems have been fixed in version 4.1+dfsg-1+deb8u5.

See Also

https://bugs.debian.org/cgi-bin/bugreport.cgi?bug=799140

https://security-tracker.debian.org/tracker/CVE-2015-5714

https://security-tracker.debian.org/tracker/CVE-2015-5715

https://security-tracker.debian.org/tracker/CVE-2015-7989

https://packages.debian.org/source/jessie/wordpress

https://www.debian.org/security/2015/dsa-3375

Plugin Details

Severity: Medium

ID: 86448

File Name: debian_DSA-3375.nasl

Version: 2.11

Type: local

Agent: unix

Published: 10/20/2015

Updated: 1/11/2021

Supported Sensors: Agentless Assessment, Continuous Assessment, Frictionless Assessment Agent, Nessus Agent, Nessus

Risk Information

VPR

Risk Factor: Low

Score: 3.0

CVSS v2

Risk Factor: Medium

Base Score: 4.3

Vector: CVSS2#AV:N/AC:M/Au:N/C:N/I:P/A:N

CVSS v3

Risk Factor: Medium

Base Score: 6.1

Vector: CVSS:3.0/AV:N/AC:L/PR:N/UI:R/S:C/C:L/I:L/A:N

Vulnerability Information

CPE: cpe:/o:debian:debian_linux:8.0, p-cpe:/a:debian:debian_linux:wordpress

Required KB Items: Host/local_checks_enabled, Host/Debian/release, Host/Debian/dpkg-l

Patch Publication Date: 10/19/2015

Reference Information

CVE: CVE-2015-5714, CVE-2015-5715, CVE-2015-7989

DSA: 3375