Bug 1044816

Summary: wordpress: possible information leak flaw reported on Full Disclosure
Product: [Other] Security Response Reporter: Murray McAllister <mmcallis>
Component: vulnerabilityAssignee: Red Hat Product Security <security-response-team>
Status: CLOSED ERRATA QA Contact:
Severity: medium Docs Contact:
Priority: medium    
Version: unspecifiedCC: fedora, gwync
Target Milestone: ---Keywords: Security
Target Release: ---   
Hardware: All   
OS: Linux   
Whiteboard:
Fixed In Version: Doc Type: Bug Fix
Doc Text:
Story Points: ---
Clone Of: Environment:
Last Closed: 2021-10-20 10:42:27 UTC Type: ---
Regression: --- Mount Type: ---
Documentation: --- CRM:
Verified Versions: Category: ---
oVirt Team: --- RHEL 7.3 requirements from Atomic Host:
Cloudforms Team: --- Target Upstream Version:

Description Murray McAllister 2013-12-19 04:13:17 UTC
A possible information leak flaw was reported to the Full Disclosure mailing list:

http://seclists.org/fulldisclosure/2013/Dec/145

No details are provided, and another flaw may be need to be used in conjunction in order to trigger the reported information leak.

Regarding the other flaws in that post, based on the version numbers Fedora and EPEL would not be affected by the reported CSRF and DoS issues.

Filing this (fairly useless) bug in case there is a version later than 3.8 we can upgrade to soon.

Comment 1 Murray McAllister 2013-12-19 04:15:32 UTC
There have been other reports without the details:

http://seclists.org/fulldisclosure/2013/Dec/46

Feel free to close not a bug as there is not much we can do at the moment.