Fedora, Ubuntu publish wrong advisories for CVE-2007-6318

看板Bugtraq作者時間18年前 (2008/03/23 01:42), 編輯推噓0(000)
留言0則, 0人參與, 最新討論串1/1
--VS++wcV0S1rZb1Fb Content-Type: text/plain; charset=utf-8 Content-Disposition: inline Content-Transfer-Encoding: quoted-printable I have just found some false changelogs and advisories published about a WordPress vuln I published a while ago. Fedora: https://www.redhat.com/archives/fedora-package-announce/2008-January/msg000= 79.html Ubuntu: https://bugs.launchpad.net/debian/+source/wordpress/+bug/181416 What they have fixed is another vuln published by Michael Brooks, about an access control failure in WordPress, instead of SQL injection. The detail of concerned vuln is available at http://xforce.iss.net/xforce/xfdb/39409 CVE-2007-6318 is NOT fixed as of version 2.3.3. Abel --=20 Abel Cheung (GPG Key: 0xC67186FF) Key fingerprint: 671C C7AE EFB5 110C D6D1 41EE 4152 E1F1 C671 86FF -------------------------------------------------------------------- * My blog - http://me.abelcheung.org/ * Opensource Application Knowledge Assoc. - http://oaka.org/ --VS++wcV0S1rZb1Fb Content-Type: application/pgp-signature; name="signature.asc" Content-Description: Digital signature Content-Disposition: inline -----BEGIN PGP SIGNATURE----- Version: GnuPG v1.4.6 (GNU/Linux) iD8DBQFH5Ei9QVLh8cZxhv8RAr4TAJ9/0co59SZyFB6qQ0DtnExnl6tOkwCeL39E 7Z0HA6dLChpJ/2q9aE2uXaY= =Ve7v -----END PGP SIGNATURE----- --VS++wcV0S1rZb1Fb--
文章代碼(AID): #17vKKZ00 (Bugtraq)