New SQL Injection vulnerability?
-
Gentoo is reporting that all WordPress versions < 2 are vulnerable if comments are enabled. Yet I’m not finding a warning prominent on ww.wp.xz.cn or instructions on how to patch 1.5.x versions to fix this. What’s up with it?
(See http://www.gentoo.org/security/en/glsa/glsa-200603-01.xml)
-
Thanks FruitFly. I think, now that I made sure all my 1.5.2 installs are set correctly, I’ll just wait “until” 2.0.2 lands – I don’t really have anything I HAVE to leave on the earlier version…. it’s just laziness mostly (and the fact that one upgrade I DID for some reason was a total nightmare….)
Just for clarification purposes and stuff, isn’t the latest from the svn branch “supposedly going to be” the 2.0.2 version.. Just wasn’t sure.. :/ I keep grabbing files every time I see new replies about the files in the email box lol..
http://svn.automattic.com/wordpress/branches/2.0/
I have the 2.1 alpha1 on a test blog now..but, just not sure on which is supposed to be what…
spencerp
I haven’t been running 1.5.2 since 2.0 came out, so I’ll just have to wait like the others on 2.0.2 then I guess.. =)
Yeah, I think the stuff on svn is absolutely the latest. I just can’t be bothered with svn – what a PITA….
Yeah, I think the stuff on svn is absolutely the latest. I just can’t be bothered with svn – what a PITA….
Haha, ok..I was figuring that..just wanted to make sure. =) Yeah, it took me forever to get a good working SVN program/software to work on my PC, then I downloaded TortoiseSVN-1.3.2.5840-svn-1.3.0 and it installed like a charm and didn’t take me long to figure out how to use it..
Also, will it hurt to upgrade to that latest SVN release or whatever? I mean.. I know 2.0.2 is coming real soon, like tomorrow or within the week, but I tend to get a little impatient lmao! I dunno, maybe I’ll just wait then..
spencerp
Don’t know, spence. I’m just waiting now….
As to svn – it’s not the client (well, it is/WAS, but anyway….), it’s the fact that in order to utilize it appropriately, you either have to camp on the svn page and download something new every time it hits, then check diffs, etc., use winmerge or something or installs, OR you have to set up a cron job to at least handle the grabs.
I can’t be bothered. HOWEVER – I am NOT happy that the mailing lists I use to TRY to keep on top of issues like this one just happen to not be sending me any mail right now. Regardless that I’m still registered for them, and that my email has not changed.
Don’t know, spence. I’m just waiting now….
Yeah, I my as well also, no need to upgrade to the latest svn whatever..and then do an “official just to be sure” upgrade again in a day or so..
But, I could just do it on test blog though once…see what happens… =) Love the Bookmarks feature and a few others, in the CP… in the soon to be release lol..
As to svn – it’s not the client (well, it is/WAS, but anyway….), it’s the fact that in order to utilize it appropriately, you either have to camp on the svn page and download something new every time it hits, then check diffs, etc., use winmerge or something or installs, OR you have to set up a cron job to at least handle the grabs.
Yeah,.. I am not “familiar” or whatever with the whole svn thing…but had tried this, which didn’t work for me:
svn co http://svn.automattic.com/wordpress/trunk/Used this for the export from box, which worked:
http://svn.automattic.com/wordpress/branches/2.0/Just had it all go into an empty folder..and I just kept grabbing files and had viewed the “supposed” changes in the emails and on hard drive.. had two separate folders one for revised ones one for the original downloaded ones..
I can’t be bothered. HOWEVER – I am NOT happy that the mailing lists I use to TRY to keep on top of issues like this one just happen to not be sending me any mail right now. Regardless that I’m still registered for them, and that my email has not changed.
Hmmm..that’s weird.. =( If you use the same as the one for the wp-forum mailing lists…I’ll try and forward one of the wp-testers list emails once.. If that won’t work, maybe try changing the email addy or adding a new one once..I dunno V. =(
spencerp
Oh, and by the way, I just setup a CVS version of the phpBB3 forum now hehe. Of course I’ll have to get familiar with it all.. How to add subforums and what not lol!
to answer a question off the previous page —
there is a function inside functions-post.php that looks to be checking against the blacklist, yes.
function wp_blacklist_check($author, $email, $url, $comment, $user_ip, $user_agent) {
global $wpdb; ...Thanks spence. I got yours just fine, and my that’s an interesting one….
I replied to the last one I got, which was yours from early yesterday…. not one damn thing since until your forward.
VERY interesting.
There may be some very good news soon π
THAT would be lovely…. seriously.
“address a security bug” ahem, me thinks we read the same groups
The topic ‘New SQL Injection vulnerability?’ is closed to new replies.