DFN-CERT-2017-1933 WordPress: Eine Schwachstelle ermöglicht einen SQL-Injection-Angriff [Linux][Fedora][Apple][Windows]

Liebe Kolleginnen und Kollegen,

bitte beachten Sie die folgende Sicherheitsmeldung.

Betroffene Software:

WordPress < 4.8.3 Betroffene Plattformen: Apple Mac OS X macOS Sierra GNU/Linux Microsoft Windows Red Hat Fedora 25 Red Hat Fedora 26 Red Hat Fedora 27 Extra Packages for Red Hat Enterprise Linux 6 Extra Packages for Red Hat Enterprise Linux 7 Eine Schwachstelle in WordPress ermöglicht einem entfernten, nicht authentisierten Angreifer einen SQL-Injection-Angriff. Der Hersteller hat die WordPress Version 4.8.3 zur Behebung der Schwachstelle als 'Security Release' veröffentlicht. Für Fedora 25, 26, 27 sowie Fedora EPEL 6 und 7 stehen Sicherheitsupdates in Form des Pakets 'wordpress-4.8.3-1' im Status 'pending' zur Verfügung. Patch: Fedora Security Update FEDORA-2017-6fd6877975 (Fedora 26, wordpress-4.8.3-1.fc26) https://bodhi.fedoraproject.org/updates/FEDORA-2017-6fd6877975

Patch:

Fedora Security Update FEDORA-2017-9d0ff8d851 (Fedora 25,
wordpress-4.8.3-1.fc25)

https://bodhi.fedoraproject.org/updates/FEDORA-2017-9d0ff8d851

Patch:

Fedora Security Update FEDORA-2017-f293e717e2 (Fedora 27,
wordpress-4.8.3-1.fc27)

https://bodhi.fedoraproject.org/updates/FEDORA-2017-f293e717e2

Patch:

Fedora Security Update FEDORA-EPEL-2017-29f7b67071 (Fedora EPEL 6,
wordpress-4.8.3-1.el6)

https://bodhi.fedoraproject.org/updates/FEDORA-EPEL-2017-29f7b67071

Patch:

Fedora Security Update FEDORA-EPEL-2017-95bf973a7d (Fedora EPEL 7,
wordpress-4.8.3-1.el7)

https://bodhi.fedoraproject.org/updates/FEDORA-EPEL-2017-95bf973a7d

Patch:

WordPress 4.8.3 Release Notes

https://wordpress.org/news/2017/10/wordpress-4-8-3-security-release/

WORDPRESS-4-8-3-A: Schwachstelle in WordPress ermöglicht
SQL-Injection-Angriff

Die Funktion ‘$wpdb->prepare()’ von WordPress vor Version 4.8.3 kann
unerwartete und unsichere Anfragen erzeugen, wodurch eine SQL-Injection
(SQLi) möglich ist. WordPress Core ist nicht direkt verwundbar, aber Plugins
und Themes könnten versehentlich die Schwachstelle hervorrufen.

Referenzen:

Dieses Advisory finden Sie auch im DFN-CERT Portal unter:
https://portal.cert.dfn.de/adv/DFN-CERT-2017-1933/

Fedora Security Update FEDORA-2017-6fd6877975 (Fedora 26,
wordpress-4.8.3-1.fc26):
https://bodhi.fedoraproject.org/updates/FEDORA-2017-6fd6877975

Fedora Security Update FEDORA-2017-9d0ff8d851 (Fedora 25,
wordpress-4.8.3-1.fc25):
https://bodhi.fedoraproject.org/updates/FEDORA-2017-9d0ff8d851

Fedora Security Update FEDORA-2017-f293e717e2 (Fedora 27,
wordpress-4.8.3-1.fc27):
https://bodhi.fedoraproject.org/updates/FEDORA-2017-f293e717e2

Fedora Security Update FEDORA-EPEL-2017-29f7b67071 (Fedora EPEL 6,
wordpress-4.8.3-1.el6):
https://bodhi.fedoraproject.org/updates/FEDORA-EPEL-2017-29f7b67071

Fedora Security Update FEDORA-EPEL-2017-95bf973a7d (Fedora EPEL 7,
wordpress-4.8.3-1.el7):
https://bodhi.fedoraproject.org/updates/FEDORA-EPEL-2017-95bf973a7d

WordPress 4.8.3 Release Notes:
https://wordpress.org/news/2017/10/wordpress-4-8-3-security-release/

(c) DFN-CERT Services GmbH, all rights reserved!
Die Weiterverbreitung ist mit Hinweis auf den Copyrightinhaber innerhalb der
eigenen Einrichtung erlaubt. Eine darüber hinausgehende Verbreitung bedarf
des schriftlichen Einverständnisses des Rechteinhabers.

Nach oben