Bug 1044816 - wordpress: possible information leak flaw reported on Full Disclosure
Summary: wordpress: possible information leak flaw reported on Full Disclosure
Keywords:
Status: CLOSED ERRATA
Alias: None
Product: Security Response
Classification: Other
Component: vulnerability
Version: unspecified
Hardware: All
OS: Linux
medium
medium
Target Milestone: ---
Assignee: Red Hat Product Security
QA Contact:
URL:
Whiteboard:
Depends On:
Blocks:
TreeView+ depends on / blocked
 
Reported: 2013-12-19 04:13 UTC by Murray McAllister
Modified: 2021-10-20 10:42 UTC (History)
2 users (show)

Fixed In Version:
Doc Type: Bug Fix
Doc Text:
Clone Of:
Environment:
Last Closed: 2021-10-20 10:42:27 UTC


Attachments (Terms of Use)

Description Murray McAllister 2013-12-19 04:13:17 UTC
A possible information leak flaw was reported to the Full Disclosure mailing list:

http://seclists.org/fulldisclosure/2013/Dec/145

No details are provided, and another flaw may be need to be used in conjunction in order to trigger the reported information leak.

Regarding the other flaws in that post, based on the version numbers Fedora and EPEL would not be affected by the reported CSRF and DoS issues.

Filing this (fairly useless) bug in case there is a version later than 3.8 we can upgrade to soon.

Comment 1 Murray McAllister 2013-12-19 04:15:32 UTC
There have been other reports without the details:

http://seclists.org/fulldisclosure/2013/Dec/46

Feel free to close not a bug as there is not much we can do at the moment.


Note You need to log in before you can comment on or make changes to this bug.