Debian Security Advisory
DSA-2138-1 wordpress -- SQL injection
- Date Reported:
- 29 Dec 2010
- Affected Packages:
- wordpress
- Vulnerable:
- Yes
- Security database references:
- In Mitre's CVE dictionary: CVE-2010-4257.
- More information:
-
Vladimir Kolesnikov discovered a SQL injection vulnerability in WordPress, a weblog manager. An authenticated user could execute arbitrary SQL commands via the Send Trackbacks field.
For the stable distribution (lenny), this problem has been fixed in version 2.5.1-11+lenny4.
For the unstable distribution (sid), and the testing distribution (squeeze), this problem has been fixed in version 3.0.2-1.
We recommend that you upgrade your wordpress package.
Further information about Debian Security Advisories, how to apply these updates to your system and frequently asked questions can be found at: https://www.debian.org/security/