CVE-2008-5695: New security issue

Related Vulnerabilities: CVE-2008-5695  

Debian Bug report logs - #510786
CVE-2008-5695: New security issue

version graph

Reported by: Moritz Muehlenhoff <jmm@debian.org>

Date: Sun, 4 Jan 2009 21:18:01 UTC

Severity: important

Tags: security

Merged with 513959

Fixed in versions wordpress/2.3.2-1, 2.3.2-1

Done: Giuseppe Iuculano <giuseppe@iuculano.it>

Bug is archived. No further changes may be made.

Toggle useless messages

View this report as an mbox folder, status mbox, maintainer mbox


Report forwarded to debian-bugs-dist@lists.debian.org, Andrea De Iacovo <andrea.de.iacovo@gmail.com>:
Bug#510786; Package wordpress. (Sun, 04 Jan 2009 21:18:04 GMT) (full text, mbox, link).


Acknowledgement sent to Moritz Muehlenhoff <jmm@debian.org>:
New Bug report received and forwarded. Copy sent to Andrea De Iacovo <andrea.de.iacovo@gmail.com>. (Sun, 04 Jan 2009 21:18:04 GMT) (full text, mbox, link).


Message #5 received at submit@bugs.debian.org (full text, mbox, reply):

From: Moritz Muehlenhoff <jmm@debian.org>
To: Debian Bug Tracking System <submit@bugs.debian.org>
Subject: CVE-2008-5695: New security issue
Date: Sun, 04 Jan 2009 22:16:06 +0100
Package: wordpress
Severity: important

A new security issue has been found in wordpress, please see
this link for some references:
http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2008-5695

Cheers,
        Moritz

-- System Information:
Debian Release: 5.0
  APT prefers unstable
  APT policy: (500, 'unstable')
Architecture: i386 (i686)

Kernel: Linux 2.6.26-1-686 (SMP w/1 CPU core)
Locale: LANG=C, LC_CTYPE=de_DE.ISO-8859-15@euro (charmap=ISO-8859-15)
Shell: /bin/sh linked to /bin/bash

Versions of packages wordpress depends on:
pn  apache2 | httpd               <none>     (no description available)
pn  libapache2-mod-php5 | php5 |  <none>     (no description available)
pn  libjs-prototype               <none>     (no description available)
pn  libjs-scriptaculous           <none>     (no description available)
pn  libphp-phpmailer              <none>     (no description available)
pn  php5-gd | php4-gd             <none>     (no description available)
pn  php5-mysql | php4-mysql       <none>     (no description available)
pn  tinymce                       <none>     (no description available)
pn  virtual-mysql-client          <none>     (no description available)

wordpress recommends no packages.

Versions of packages wordpress suggests:
pn  virtual-mysql-server          <none>     (no description available)




Tags added: security Request was from Nico Golde <nion@debian.org> to control@bugs.debian.org. (Mon, 05 Jan 2009 14:51:08 GMT) (full text, mbox, link).


Information forwarded to debian-bugs-dist@lists.debian.org:
Bug#510786; Package wordpress. (Tue, 06 Jan 2009 16:18:02 GMT) (full text, mbox, link).


Acknowledgement sent to Andrea De Iacovo <andrea.de.iacovo@gmail.com>:
Extra info received and forwarded to list. (Tue, 06 Jan 2009 16:18:02 GMT) (full text, mbox, link).


Message #12 received at 510786@bugs.debian.org (full text, mbox, reply):

From: Andrea De Iacovo <andrea.de.iacovo@gmail.com>
To: Moritz Muehlenhoff <jmm@debian.org>, 510786@bugs.debian.org
Subject: Re: Bug#510786: CVE-2008-5695: New security issue
Date: Tue, 06 Jan 2009 17:12:13 +0100
[Message part 1 (text/plain, inline)]
> Package: wordpress
> Severity: important
> 
> A new security issue has been found in wordpress, please see
> this link for some references:
> http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2008-5695

Thank you for reporting.

I'll check this out as soon as possibile.

Cheers.

Andrea

[signature.asc (application/pgp-signature, inline)]

Merged 510786 513959. Request was from Steffen Joeris <steffen.joeris@skolelinux.de> to control@bugs.debian.org. (Mon, 02 Feb 2009 20:31:41 GMT) (full text, mbox, link).


Bug Marked as fixed in versions wordpress/2.3.2-1. Request was from Giuseppe Iuculano <giuseppe@iuculano.it> to control@bugs.debian.org. (Tue, 11 Aug 2009 11:54:05 GMT) (full text, mbox, link).


Added tag(s) pending. Request was from Giuseppe Iuculano <giuseppe@iuculano.it> to control@bugs.debian.org. (Sat, 15 Aug 2009 11:33:04 GMT) (full text, mbox, link).


Removed tag(s) pending. Request was from Giuseppe Iuculano <giuseppe@iuculano.it> to control@bugs.debian.org. (Sat, 15 Aug 2009 11:39:02 GMT) (full text, mbox, link).


Reply sent to Giuseppe Iuculano <giuseppe@iuculano.it>:
You have taken responsibility. (Sun, 16 Aug 2009 15:27:03 GMT) (full text, mbox, link).


Notification sent to Moritz Muehlenhoff <jmm@debian.org>:
Bug acknowledged by developer. (Sun, 16 Aug 2009 15:27:03 GMT) (full text, mbox, link).


Message #25 received at 510786-done@bugs.debian.org (full text, mbox, reply):

From: Giuseppe Iuculano <giuseppe@iuculano.it>
To: 510786-done@bugs.debian.org
Subject: fixed
Date: Sun, 16 Aug 2009 17:19:46 +0200
[Message part 1 (text/plain, inline)]
Version: 2.3.2-1

This bug was fixed in wordpress 2.3.2-1

[signature.asc (application/pgp-signature, attachment)]

Reply sent to Giuseppe Iuculano <giuseppe@iuculano.it>:
You have taken responsibility. (Sun, 16 Aug 2009 15:27:04 GMT) (full text, mbox, link).


Notification sent to Steffen Joeris <steffen.joeris@skolelinux.de>:
Bug acknowledged by developer. (Sun, 16 Aug 2009 15:27:04 GMT) (full text, mbox, link).


Bug archived. Request was from Debbugs Internal Request <owner@bugs.debian.org> to internal_control@bugs.debian.org. (Mon, 14 Sep 2009 07:37:20 GMT) (full text, mbox, link).


Send a report that this bug log contains spam.


Debian bug tracking system administrator <owner@bugs.debian.org>. Last modified: Wed Jun 19 17:57:45 2019; Machine Name: buxtehude

Debian Bug tracking system

Debbugs is free software and licensed under the terms of the GNU Public License version 2. The current version can be obtained from https://bugs.debian.org/debbugs-source/.

Copyright © 1999 Darren O. Benham, 1997,2003 nCipher Corporation Ltd, 1994-97 Ian Jackson, 2005-2017 Don Armstrong, and many other contributors.