Common Vulnerabilities and Exposures assigned an identifier CVE-2008-5278 to the following vulnerability: Cross-site scripting (XSS) vulnerability in the self_link function in in the RSS Feed Generator (wp-includes/feed.php) for WordPress before 2.6.5 allows remote attackers to inject arbitrary web script or HTML via the Host header (HTTP_HOST variable). References: http://wordpress.org/development/2008/11/wordpress-265/ http://www.securityfocus.com/archive/1/498652 (there is also PoC available) Note: Please upgrade to latest 2.6.5 upstream version of Wordpress and also apply the patch to Wordpress-MU
This issue affects all versions of the WordPress package, as shipped with the Fedora releases of 9, 10 and devel and within the Extra Packages for the Enteprise Linux version 5 project (EPEL5). This issue affects the version of the WordPress MU package, as shipped with the Fedora release of 10.
This issue was addressed in: wordpress-2.6.5-2.fc8 wordpress-2.6.5-2.fc9 wordpress-2.6.5-2.fc10 Fedora security updates. Please update yet the Fedora EPEL5 wordpress package and Fedora 10 wordpress-mu package.
Created attachment 325086 [details] WordPress-CVE-2008-5278.diff
wordpress-2.6.5-2.fc9 has been pushed to the Fedora 9 stable repository. If problems still persist, please make note of it in this bug report.
wordpress-2.6.5-2.fc10 has been pushed to the Fedora 10 stable repository. If problems still persist, please make note of it in this bug report.
wordpress-2.6.5-2.fc8 has been pushed to the Fedora 8 stable repository. If problems still persist, please make note of it in this bug report.
wordpress-mu-2.6.5-1.fc10 has been submitted as an update for Fedora 10. http://admin.fedoraproject.org/updates/wordpress-mu-2.6.5-1.fc10
wordpress-mu-2.6.5-1.fc10 has been pushed to the Fedora 10 stable repository. If problems still persist, please make note of it in this bug report.