Follow @Openwall on Twitter for new release announcements and other news
[<prev] [next>] [thread-next>] [day] [month] [year] [list]
Message-ID: <20160108140715.GA25718@eldamar.local>
Date: Fri, 8 Jan 2016 15:07:15 +0100
From: Salvatore Bonaccorso <carnil@...ian.org>
To: OSS Security Mailinglist <oss-security@...ts.openwall.com>
Subject: CVE Request: WordPress: cross-site scripting vulnerability fixed in
 new 4.4.1 release

Hi

On 6th of January 2016, a new release of WordPress was posted,
https://wordpress.org/news/2016/01/wordpress-4-4-1-security-and-maintenance-release/

> WordPress versions 4.4 and earlier are affected by a cross-site
> scripting vulnerability that could allow a site to be compromised.
> This was reported by Crtc4L.

There is no reference to the fix, but the change seems to be

https://core.trac.wordpress.org/changeset/36185

Cf. as well https://twitter.com/brutelogic/status/685105483397619713

Can a CVE be assigned for this WordPress issue?

Regards,
Salvatore

Powered by blists - more mailing lists

Please check out the Open Source Software Security Wiki, which is counterpart to this mailing list.

Confused about mailing lists and their use? Read about mailing lists on Wikipedia and check out these guidelines on proper formatting of your messages.