Advisories ยป MGASA-2014-0254

Updated wordpress package fixes multiple vulnerabilities

Publication date: 06 Jun 2014
Type: security
Affected Mageia releases : 3 , 4
CVE: CVE-2014-0165 , CVE-2014-0166

Description

Updated wordpress package fixes security vulnerabilities:

WordPress before 3.7.2 allows remote authenticated users to publish posts
by leveraging the Contributor role, related to wp-admin/includes/post.php
and wp-admin/includes/class-wp-posts-list-table.php (CVE-2014-0165).

The wp_validate_auth_cookie function in wp-includes/pluggable.php in
WordPress before 3.7.2 does not properly determine the validity of
authentication cookies, which makes it easier for remote attackers to
obtain access via a forged cookie (CVE-2014-0166).

The wordpress package has been updated to version 3.9.1, fixing these and
other issues.
                

References

SRPMS

3/core

4/core