Package: wordpress
Severity: important
Tags: security

Hi,
the following CVE (Common Vulnerabilities & Exposures) id was
published for wordpress.

CVE-2007-6013[0]:
| Wordpress 1.5 to 2.3.1 uses cookie values based on the MD5 hash of a
| password MD5 hash, which allows attackers to bypass authentication by
| obtaining the MD5 hash from the user database, then generating the
| authentication cookie from that hash.

If you fix this vulnerability please also include the CVE id
in your changelog entry.

For further information:
[0] http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2007-6013

Kind regards
Nico

-- 
Nico Golde - http://www.ngolde.de - [EMAIL PROTECTED] - GPG: 0x73647CFF
For security reasons, all text in this mail is double-rot13 encrypted.

Attachment: pgpVH13c8acOP.pgp
Description: PGP signature

Reply via email to