Bug#906565: wordpress: CVE-2018-14028

2019-10-16 Thread Craig Small
Hmm, I'm not too sure why I said it was fixed in that version. I think there was another bug that got fixed that looked like that one. Version 4.9.x of wordpress, when their release announcements were worth something... On Thu, 17 Oct 2019 at 05:21, Markus Koschany wrote: > Hello Craig, > >

Bug#906565: wordpress: CVE-2018-14028

2019-10-16 Thread Markus Koschany
Hello Craig, while I was preparing a Wordpress update for Jessie I discovered that CVE-2018-14028 has not been fixed yet. The upstream ticket is still open https://core.trac.wordpress.org/ticket/44710 and there was no mention of a fix in the release changelog of version 4.9.8.

Bug#906565: wordpress: CVE-2018-14028

2018-08-18 Thread Salvatore Bonaccorso
Source: wordpress Version: 4.9.7+dfsg1-1 Severity: normal Tags: security upstream Forwarded: https://core.trac.wordpress.org/ticket/44710 Hi, The following vulnerability was published for wordpress, so we can track the upstream status filling the bug, I think the impact is quite limited if I