Nmap Security Scanner
*Intro
*Ref Guide
*Install Guide
*Download
*Changelog
*Book
*Docs
Security Lists
*Nmap Hackers
*Nmap Dev
*Bugtraq
*Full Disclosure
*Pen Test
*Basics
*More
Security Tools
*Pass crackers
*Sniffers
*Vuln Scanners
*Web scanners
*Wireless
*Exploitation
*Packet crafters
*More
Site News
Site Search:
Exploit World
Advertising
About/Contact
Credits
Sponsors:
edgeos

Bugtraq: Fedora, Ubuntu publish wrong advisories for CVE-2007-6318

Fedora, Ubuntu publish wrong advisories for CVE-2007-6318

From: Abel Cheung <abelcheung_at_gmail.com>
Date: Sat, 22 Mar 2008 07:46:06 +0800

I have just found some false changelogs and advisories published
about a WordPress vuln I published a while ago.

Fedora:
https://www.redhat.com/archives/fedora-package-announce/2008-January/msg00079.html

Ubuntu:
https://bugs.launchpad.net/debian/+source/wordpress/+bug/181416

What they have fixed is another vuln published by Michael Brooks,
about an access control failure in WordPress, instead of SQL injection.
The detail of concerned vuln is available at

http://xforce.iss.net/xforce/xfdb/39409

CVE-2007-6318 is NOT fixed as of version 2.3.3.

Abel

-- 
Abel Cheung   (GPG Key: 0xC67186FF)
Key fingerprint: 671C C7AE EFB5 110C D6D1  41EE 4152 E1F1 C671 86FF
--------------------------------------------------------------------
* My blog - http://me.abelcheung.org/
* Opensource Application Knowledge Assoc. - http://oaka.org/

Received on Mar 22 2008
[ Nmap | Sec Tools | Mailing Lists | Site News | About/Contact | Advertising | Privacy ]