Bug 263861

Summary: CVE-2007-4139 and more WordPress 2.2.1 security vulnerabilites
Product: [Fedora] Fedora Reporter: Alexander Koenig <alex>
Component: wordpressAssignee: John Berninger <john>
Status: CLOSED ERRATA QA Contact: Fedora Extras Quality Assurance <extras-qa>
Severity: urgent Docs Contact:
Priority: medium    
Version: 7   
Target Milestone: ---   
Target Release: ---   
Hardware: All   
OS: Linux   
Whiteboard:
Fixed In Version: 2.2.2-0.fc7 Doc Type: Bug Fix
Doc Text:
Story Points: ---
Clone Of: Environment:
Last Closed: 2007-08-29 17:27:10 UTC Type: ---
Regression: --- Mount Type: ---
Documentation: --- CRM:
Verified Versions: Category: ---
oVirt Team: --- RHEL 7.3 requirements from Atomic Host:
Cloudforms Team: --- Target Upstream Version:
Embargoed:

Description Alexander Koenig 2007-08-29 15:49:04 UTC
Description of problem:

The current release of WordPress in f7 has security issues that 
have been addressed with the current version 2.2.2:

http://wordpress.org/development/2007/08/wordpress-222-and-2011/

As one of those issues does not even require author privileges,
wordpress should be upgraded to version 2.2.2

Version-Release number of selected component (if applicable):

wordpress-2.2.1-1.fc7

Additional info:

http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2007-4139

Comment 1 John Berninger 2007-08-29 16:03:47 UTC
WP 2.2.2 is actually already in the testing repo (I just built and pushed it
there this morning).  I'll update the push request to link to this BZ/CVE.

Comment 2 Fedora Update System 2007-08-29 17:27:09 UTC
wordpress-2.2.2-0.fc7 has been pushed to the Fedora 7 stable repository.  If problems still persist, please make note of it in this bug report.