[Git][security-tracker-team/security-tracker][master] Add CVE-2019-894{2,3}/wordpress

Salvatore Bonaccorso carnil at debian.org
Wed Feb 20 09:32:29 GMT 2019


Salvatore Bonaccorso pushed to branch master at Debian Security Tracker / security-tracker


Commits:
d46c0e55 by Salvatore Bonaccorso at 2019-02-20T09:32:00Z
Add CVE-2019-894{2,3}/wordpress

- - - - -


1 changed file:

- data/CVE/list


Changes:

=====================================
data/CVE/list
=====================================
@@ -13,9 +13,12 @@ CVE-2019-8945
 CVE-2019-8944 (An Information Exposure issue in the Terraform deployment step in ...)
 	TODO: check
 CVE-2019-8943 (WordPress through 5.0.3 allows Path Traversal in wp_crop_image(). An ...)
-	TODO: check
+	- wordpress <unfixed>
+	NOTE: https://blog.ripstech.com/2019/wordpress-image-remote-code-execution/
 CVE-2019-8942 (WordPress before 4.9.9 and 5.x before 5.0.1 allows remote code ...)
-	TODO: check
+	- wordpress 5.0.1+dfsg1-1
+	NOTE: https://blog.ripstech.com/2019/wordpress-image-remote-code-execution/
+	NOTE: Issue fixed in 4.9.9 and 5.0.1 upstream
 CVE-2019-8941
 	RESERVED
 CVE-2019-8940



View it on GitLab: https://salsa.debian.org/security-tracker-team/security-tracker/commit/d46c0e55e3b101f52aeadd12b0a2c96bcd1657c1

-- 
View it on GitLab: https://salsa.debian.org/security-tracker-team/security-tracker/commit/d46c0e55e3b101f52aeadd12b0a2c96bcd1657c1
You're receiving this email because of your account on salsa.debian.org.
-------------- next part --------------
An HTML attachment was scrubbed...
URL: <http://alioth-lists.debian.net/pipermail/debian-security-tracker-commits/attachments/20190220/6539ec11/attachment.html>


More information about the debian-security-tracker-commits mailing list