OpenPKG Security Advisory
OpenPKG-SA-2006.027
Publisher Name: OpenPKG GmbH
Publisher Home: http://openpkg.com/
Advisory Id (public): OpenPKG-SA-2006.027
Advisory Type: OpenPKG Security Advisory (SA)
Advisory Directory: http://openpkg.com/go/OpenPKG-SA
Advisory Document: http://openpkg.com/go/OpenPKG-SA-2006.027
Advisory Published: 2009-07-04 05:57 UTC
Issue Id (internal): OpenPKG-SI-20061030.01
Issue First Created: 2006-10-30
Issue Last Modified: 2006-11-28
Issue Revision: 07
Subject Name: Wordpress
Subject Summary: Weblog Publishing System
Subject Home: http://www.wordpress.org/
Subject Versions: * <= 2.0.4
Vulnerability Id: none
Vulnerability Scope: global (not OpenPKG specific)
Attack Feasibility: run-time
Attack Vector: local system
Attack Impact: exposure of sensitive information
Description:
According to a vendor release announcement [0], security issues exist
in the personal publishing platform WordPress [1]. The "wp-db-backup"
plugin accepts filenames which could be used to access security
sensitive files.
References:
[0] http://markjaquith.wordpress.com/2006/10/17/changes-in-wordpress-205/
[1] http://www.wordpress.org/
Primary Package Name: wordpress
Primary Package Home: http://openpkg.org/go/package/wordpress
Affected Distribution: Affected Branch: Affected Package:
OpenPKG Enterprise E1.0-SOLID n/a
OpenPKG Community 2-STABLE-20061018 wordpress-2.0.4-2.20061018
OpenPKG Community 2-STABLE wordpress-2.0.4-2.20061018
OpenPKG Community CURRENT wordpress-2.0.4-20061013
Corrected Distribution: Corrected Branch: Corrected Package:
OpenPKG Enterprise E1.0-SOLID wordpress-2.0.5-E1.0.0
OpenPKG Community 2-STABLE-20061018 wordpress-2.0.5-2.20061030
OpenPKG Community 2-STABLE wordpress-2.0.5-2.20061030
OpenPKG Community CURRENT wordpress-2.0.5-20061029