Login
Newsletter
Werbung

Sicherheit: Cross-Site Scripting in wordpress
Aktuelle Meldungen Distributionen
Name: Cross-Site Scripting in wordpress
ID: FEDORA-2024-6a4ffde369
Distribution: Fedora
Plattformen: Fedora 40
Datum: Do, 11. Juli 2024, 06:41
Referenzen: Keine Angabe
Applikationen: wordpress

Originalnachricht

--===============7522782347783354381==

-------------------------------------------------------------------------------
-
Fedora Update Notification
FEDORA-2024-6a4ffde369
2024-07-11 01:14:50.363419
-------------------------------------------------------------------------------
-

Name : wordpress
Product : Fedora 40
Version : 6.5.5
Release : 1.fc40
URL : http://www.wordpress.org
Summary : Blog tool and publishing platform
Description :
Wordpress is an online publishing / weblog package that makes it very easy,
almost trivial, to get information out to people on the web.

Important information in /usr/share/doc/wordpress/README.fedora

-------------------------------------------------------------------------------
-
Update Information:

WordPress 6.5.5 Maintenance & Security Release
Security updates included in this release
The security team would like to thank the following people for responsibly
reporting vulnerabilities, and allowing them to be fixed in this release:
A cross-site scripting (XSS) vulnerability affecting the HTML API reported by
Dennis Snell of the WordPress Core Team, along with Alex Concha and Grzegorz
(Greg) Ziółkowski of the WordPress security team.
A cross-site scripting (XSS) vulnerability affecting the Template Part block
reported independently by Rafie Muhammad of Patchstack and during a third party
security audit.
A path traversal issue affecting sites hosted on Windows reported independently
by Rafie M & Edouard L of Patchstack, David Fifield, x89, apple502j, and
mishre.
See also the Upstream announcement
-------------------------------------------------------------------------------
-
ChangeLog:

* Tue Jul 2 2024 Remi Collet <remi@remirepo.net> - 6.5.5-1
- WordPress 6.4.2 Maintenance & Security Release
-------------------------------------------------------------------------------
-

This update can be installed with the "dnf" update program. Use
su -c 'dnf upgrade --advisory FEDORA-2024-6a4ffde369' at the command
line. For more information, refer to the dnf documentation available at
http://dnf.readthedocs.io/en/latest/command_ref.html#upgrade-command-label

All packages are signed with the Fedora Project GPG key. More details on the
GPG keys used by the Fedora Project can be found at
https://fedoraproject.org/keys
-------------------------------------------------------------------------------
-


--===============7522782347783354381==
Content-Type: text/plain; charset="utf-8"
MIME-Version: 1.0
Content-Transfer-Encoding: base64
Content-Disposition: inline

--
_______________________________________________
package-announce mailing list -- package-announce@lists.fedoraproject.org
To unsubscribe send an email to package-announce-leave@lists.fedoraproject.org
Fedora Code of Conduct: https://docs.fedoraproject.org/en-US/project/code-of-conduct/
List Guidelines: https://fedoraproject.org/wiki/Mailing_list_guidelines
List Archives: https://lists.fedoraproject.org/archives/list/package-announce@lists.fedoraproject.org
Do not reply to spam, report it: https://pagure.io/fedora-infrastructure/new_issue
--===============7522782347783354381==--
Pro-Linux
Pro-Linux @Facebook
Neue Nachrichten
Werbung