Fedora, Ubuntu publish wrong advisories for CVE-2007-6318
- To: bugtraq@xxxxxxxxxxxxxxxxx
- Subject: Fedora, Ubuntu publish wrong advisories for CVE-2007-6318
- From: Abel Cheung <abelcheung@xxxxxxxxx>
- Date: Sat, 22 Mar 2008 07:46:06 +0800
- Dkim-signature: v=1; a=rsa-sha256; c=relaxed/relaxed; d=gmail.com; s=beta; h=domainkey-signature:received:received:date:from:to:subject:message-id:mime-version:content-type:content-disposition; bh=DF1z+g2thrwiTxvwatuqRTeG6yl+6KBY/XzkP3IeBjU=; b=rpBs1S/sBHB6VxGhEfqCzIwxd/noWAQ0ykAOrZoGjMF10V/Uv7OneWPdiDoxeWh+GbmErDQadgTcNejHeQnLXFf0NsA5kyaoQGXmEwq+VEACI8m4u7oP6Um1Kr+yMa293cmNMINwQv2WN6TciAhxeUQbQf2oYXEXPjJkaQVYsiM=
- Domainkey-signature: a=rsa-sha1; c=nofws; d=gmail.com; s=beta; h=date:from:to:subject:message-id:mime-version:content-type:content-disposition; b=DSlLYsWSlVB13dvM2Q850cm++Qm6Mi86Aehny7yVmp23+gGctV0vHzitz8HPG/Iuj+8vyyv4JxF/sDB3YUQrJx8K4eWrZ8aUoc7YK8Nt3dj9SDdFPoCBkyLMGTZuxJ9Z5PT7svmIG2nIyP0a7ysYAjLIUOAF7nMUexsXTAVMm+8=
- List-help: <mailto:bugtraq-help@securityfocus.com>
- List-id: <bugtraq.list-id.securityfocus.com>
- List-post: <mailto:bugtraq@securityfocus.com>
- List-subscribe: <mailto:bugtraq-subscribe@securityfocus.com>
- List-unsubscribe: <mailto:bugtraq-unsubscribe@securityfocus.com>
- Mailing-list: contact bugtraq-help@xxxxxxxxxxxxxxxxx; run by ezmlm
I have just found some false changelogs and advisories published
about a WordPress vuln I published a while ago.
Fedora:
https://www.redhat.com/archives/fedora-package-announce/2008-January/msg00079.html
Ubuntu:
https://bugs.launchpad.net/debian/+source/wordpress/+bug/181416
What they have fixed is another vuln published by Michael Brooks,
about an access control failure in WordPress, instead of SQL injection.
The detail of concerned vuln is available at
http://xforce.iss.net/xforce/xfdb/39409
CVE-2007-6318 is NOT fixed as of version 2.3.3.
Abel
--
Abel Cheung (GPG Key: 0xC67186FF)
Key fingerprint: 671C C7AE EFB5 110C D6D1 41EE 4152 E1F1 C671 86FF
--------------------------------------------------------------------
* My blog - http://me.abelcheung.org/
* Opensource Application Knowledge Assoc. - http://oaka.org/
Attachment:
signature.asc
Description: Digital signature