- Package:
- src:wordpress
- Source:
- wordpress
- Submitter:
- Salvatore Bonaccorso
- Date:
- 2019-10-17 01:51:03 UTC
- Severity:
- normal
Hi, The following vulnerability was published for wordpress, so we can track the upstream status filling the bug, I think the impact is quite limited if I understand correctly. CVE-2018-14028[0]: | In WordPress 4.9.7, plugins uploaded via the admin area are not | verified as being ZIP files. This allows for PHP files to be uploaded. | Once a PHP file is uploaded, the plugin extraction fails, but the PHP | file remains in a predictable wp-content/uploads location, allowing | for an attacker to then execute the file. This represents a security | risk in limited scenarios where an attacker (who does have the | required capabilities for plugin uploads) cannot simply place | arbitrary PHP code into a valid plugin ZIP file and upload that | plugin, because a machine's wp-content/plugins directory permissions | were set up to block all new plugins. If you fix the vulnerability please also make sure to include the CVE (Common Vulnerabilities & Exposures) id in your changelog entry. For further information see: [0] https://security-tracker.debian.org/tracker/CVE-2018-14028 https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2018-14028 Please adjust the affected versions in the BTS as needed. Regards, Salvatore
We believe that the bug you reported is fixed in the latest version of
wordpress, which is due to be installed in the Debian FTP archive.
A summary of the changes between this version and the previous one is
attached.
Thank you for reporting the bug, which will now be closed. If you
have further comments please address them to 906565@bugs.debian.org,
and the maintainer will reopen the bug report if appropriate.
Debian distribution maintenance software
pp.
Craig Small <csmall@debian.org> (supplier of updated wordpress package)
(This message was generated automatically at their request; if you
believe that there is a problem with it please contact the archive
administrators by mailing ftpmaster@ftp-master.debian.org)
Format: 1.8
Date: Tue, 21 Aug 2018 20:47:44 +1000
Source: wordpress
Binary: wordpress wordpress-l10n wordpress-theme-twentysixteen wordpress-theme-twentyfifteen wordpress-theme-twentyseventeen
Architecture: source all
Version: 4.9.8+dfsg1-1
Distribution: unstable
Urgency: medium
Maintainer: Craig Small <csmall@debian.org>
Changed-By: Craig Small <csmall@debian.org>
Description:
wordpress - weblog manager
wordpress-l10n - weblog manager - language files
wordpress-theme-twentyfifteen - weblog manager - twentytfifteen theme files
wordpress-theme-twentyseventeen - weblog manager - twentyseventeen theme files
wordpress-theme-twentysixteen - weblog manager - twentysixteen theme files
Closes: 906565
Changes:
wordpress (4.9.8+dfsg1-1) unstable; urgency=medium
.
* New upstream source
Verify plugin uploads CVE-2018-14028 Closes: #906565
Checksums-Sha1:
26bbef2d37f860b96ab75a15be7c85e1b0542670 2463 wordpress_4.9.8+dfsg1-1.dsc
179d2623dd9d9dc83875769c30211d9473ac2642 6834808 wordpress_4.9.8+dfsg1.orig.tar.xz
28703bfb70c57b05c7e04a0a74e9f2b548d56254 6779224 wordpress_4.9.8+dfsg1-1.debian.tar.xz
1be260616cc16341bf7f76c607c04273cd131e68 4382868 wordpress-l10n_4.9.8+dfsg1-1_all.deb
99272ff7fabb02f265490c2b206e98a9c2c43599 701352 wordpress-theme-twentyfifteen_4.9.8+dfsg1-1_all.deb
bfb78d0a67045edc3889f8dcc993f96c1d9ffcb6 942120 wordpress-theme-twentyseventeen_4.9.8+dfsg1-1_all.deb
5445348a03fe0d994b4f7f23ff9edd89947a80fd 589916 wordpress-theme-twentysixteen_4.9.8+dfsg1-1_all.deb
17ec8922f4ee189cfb34acd0f9aa332a03275762 4581692 wordpress_4.9.8+dfsg1-1_all.deb
c2adfc8fed3747ab78ec68b37d557c6448f6b2e5 7426 wordpress_4.9.8+dfsg1-1_amd64.buildinfo
Checksums-Sha256:
da02d52d07efd4b2ab54d15a45fee760dda4eb3c01e8b1d5b2be8030ca963f25 2463 wordpress_4.9.8+dfsg1-1.dsc
3f1e86a3f9bad8dc7c01eec598c7313f8592ce17a9e68331c6edba9140022187 6834808 wordpress_4.9.8+dfsg1.orig.tar.xz
1c81448edfe121a08c05067393663cc39a938d601ebf3d7ef2dd1bddc43d3f82 6779224 wordpress_4.9.8+dfsg1-1.debian.tar.xz
a07a4599ae35c2ccc7c311c700dacb2af16291c080e0b1ce8a118fc7742a7eae 4382868 wordpress-l10n_4.9.8+dfsg1-1_all.deb
1b4ace7b1f38e58cb6c0022831e2c1a587e48f2371d42c17b5b1e2dbc0b82fe1 701352 wordpress-theme-twentyfifteen_4.9.8+dfsg1-1_all.deb
46be6bc86f5653c7462bd856b43985207affb46a74bd4a7f3a32dc41dcbadc9e 942120 wordpress-theme-twentyseventeen_4.9.8+dfsg1-1_all.deb
3a305eb4566637985cc944f1e1fa52079cadfef7b895f61f60b03e1c38bbbc22 589916 wordpress-theme-twentysixteen_4.9.8+dfsg1-1_all.deb
bbbd6c44711e74d4eeb8dd8c2c75db57fee73df2f3ca0190f10b1cc034c3354a 4581692 wordpress_4.9.8+dfsg1-1_all.deb
99cfeee86193901c7f108833e984fd09db80713ca17f0d3d36faab83876cbb20 7426 wordpress_4.9.8+dfsg1-1_amd64.buildinfo
Files:
db5fc8da2ea6a25ff692f6e0a19ae483 2463 web optional wordpress_4.9.8+dfsg1-1.dsc
b361e7ca2bd149a952cfadacd0651ee4 6834808 web optional wordpress_4.9.8+dfsg1.orig.tar.xz
09a3930f59db58710b817d2bc50a6970 6779224 web optional wordpress_4.9.8+dfsg1-1.debian.tar.xz
001ce271af3e392130c790d4c09b8c59 4382868 localization optional wordpress-l10n_4.9.8+dfsg1-1_all.deb
6c14c43a7e05b34f7384d1e75dc710d5 701352 web optional wordpress-theme-twentyfifteen_4.9.8+dfsg1-1_all.deb
e645301c318ccc2ac26a69dc670fc967 942120 web optional wordpress-theme-twentyseventeen_4.9.8+dfsg1-1_all.deb
94ff036b8a4a670857d2b030eae56e5f 589916 web optional wordpress-theme-twentysixteen_4.9.8+dfsg1-1_all.deb
e74b4d54f2e3eb76cbab51c8118efa06 4581692 web optional wordpress_4.9.8+dfsg1-1_all.deb
d8aa3b508e9c42ff50acafce21786ff7 7426 web optional wordpress_4.9.8+dfsg1-1_amd64.buildinfo
-----BEGIN PGP SIGNATURE-----
iQIzBAEBCgAdFiEEXT3w9TizJ8CqeneiAiFmwP88hOMFAlt78v8ACgkQAiFmwP88
hOOItw/9HMYMTQ//JW7iUxXa5ENOpi431MBfU/FE93t12YaOWmOm1p5TO2W08kn3
+d8oTvrou26MedOd59DcOSt1wXK5U/Wv8iL641xEZgU44caCLOAj/0Rwd9OsGqwI
MOIKyksvB5mm42EaTNH9ZZx9x6dhlfR2ps0KBpazosYMEh7GYUYxK2OLXDX1BBmf
Q8diBDQCWL83nFXO3lntmz8YGJ5p/bVBpg6Vy1UaD3XO8uQFN4ArLI/ZOcWpo/Ig
2YX7WloExjzOcyhJ5KDJRC3GQ0lpjN+BQWDoMIg9Y3bu9c5VMeN5pYhhdjn+H/FH
y1GOnbQehxdLUWaG1JrrCEg28w3hdmK1N/BvBUkV4I3eMGyF8ycBpcRwdpReAgR8
K9R8sGup8f7fEiL1L85dVVcvpYk7nxuuM1PbXNOY+UsYkbxWO244UaTRIUOkzNUQ
ILOHH9EihR8rGot0UMhXFKdmlEucGP2TeS7izRdNdclfoK8nN6FFOoXyF69DHcZw
HyBXkcUVxadUK4U/XkGciCghhjoH5bGDdJkqJONP5mPssogzWqVZLUGQiKsb1ySh
eI/X6Zl3nbCSLozWmZwoEiE2ZmMaUCCXLKIsfcN7S039NCO8OhJ3e6Hoza7v6OmS
EZab9XrvRMg9CvsJQOmBWcMLYF478M/WHhICFzXYbmboHjFoBv4=
=q0Mt
-----END PGP SIGNATURE-----
Hello Craig, while I was preparing a Wordpress update for Jessie I discovered that CVE-2018-14028 has not been fixed yet. The upstream ticket is still open https://core.trac.wordpress.org/ticket/44710 and there was no mention of a fix in the release changelog of version 4.9.8. https://wordpress.org/support/wordpress-version/version-4.9.8/ I believe it is best to keep this bug report open until upstream closes 44710 eventually. Regards, Markus
Hmm, I'm not too sure why I said it was fixed in that version. I think there was another bug that got fixed that looked like that one. Version 4.9.x of wordpress, when their release announcements were worth something...