Liebe Kolleginnen und Kollegen,
bitte beachten Sie die folgende Sicherheitsmeldung.
Betroffene Software:
WordPress < 4.8.3 Betroffene Plattformen: Apple Mac OS X macOS Sierra GNU/Linux Microsoft Windows Red Hat Fedora 25 Red Hat Fedora 26 Red Hat Fedora 27 Extra Packages for Red Hat Enterprise Linux 6 Extra Packages for Red Hat Enterprise Linux 7 Eine Schwachstelle in WordPress ermöglicht einem entfernten, nicht authentisierten Angreifer einen SQL-Injection-Angriff. Der Hersteller hat die WordPress Version 4.8.3 zur Behebung der Schwachstelle als 'Security Release' veröffentlicht. Für Fedora 25, 26, 27 sowie Fedora EPEL 6 und 7 stehen Sicherheitsupdates in Form des Pakets 'wordpress-4.8.3-1' im Status 'pending' zur Verfügung. Patch: Fedora Security Update FEDORA-2017-6fd6877975 (Fedora 26, wordpress-4.8.3-1.fc26) https://bodhi.fedoraproject.org/updates/FEDORA-2017-6fd6877975
Patch:
Fedora Security Update FEDORA-2017-9d0ff8d851 (Fedora 25,
wordpress-4.8.3-1.fc25)
https://bodhi.fedoraproject.org/updates/FEDORA-2017-9d0ff8d851
Patch:
Fedora Security Update FEDORA-2017-f293e717e2 (Fedora 27,
wordpress-4.8.3-1.fc27)
https://bodhi.fedoraproject.org/updates/FEDORA-2017-f293e717e2
Patch:
Fedora Security Update FEDORA-EPEL-2017-29f7b67071 (Fedora EPEL 6,
wordpress-4.8.3-1.el6)
https://bodhi.fedoraproject.org/updates/FEDORA-EPEL-2017-29f7b67071
Patch:
Fedora Security Update FEDORA-EPEL-2017-95bf973a7d (Fedora EPEL 7,
wordpress-4.8.3-1.el7)
https://bodhi.fedoraproject.org/updates/FEDORA-EPEL-2017-95bf973a7d
Patch:
WordPress 4.8.3 Release Notes
https://wordpress.org/news/2017/10/wordpress-4-8-3-security-release/
WORDPRESS-4-8-3-A: Schwachstelle in WordPress ermöglicht
SQL-Injection-Angriff
Die Funktion ‘$wpdb->prepare()’ von WordPress vor Version 4.8.3 kann
unerwartete und unsichere Anfragen erzeugen, wodurch eine SQL-Injection
(SQLi) möglich ist. WordPress Core ist nicht direkt verwundbar, aber Plugins
und Themes könnten versehentlich die Schwachstelle hervorrufen.
Referenzen:
Dieses Advisory finden Sie auch im DFN-CERT Portal unter:
https://portal.cert.dfn.de/adv/DFN-CERT-2017-1933/
Fedora Security Update FEDORA-2017-6fd6877975 (Fedora 26,
wordpress-4.8.3-1.fc26):
https://bodhi.fedoraproject.org/updates/FEDORA-2017-6fd6877975
Fedora Security Update FEDORA-2017-9d0ff8d851 (Fedora 25,
wordpress-4.8.3-1.fc25):
https://bodhi.fedoraproject.org/updates/FEDORA-2017-9d0ff8d851
Fedora Security Update FEDORA-2017-f293e717e2 (Fedora 27,
wordpress-4.8.3-1.fc27):
https://bodhi.fedoraproject.org/updates/FEDORA-2017-f293e717e2
Fedora Security Update FEDORA-EPEL-2017-29f7b67071 (Fedora EPEL 6,
wordpress-4.8.3-1.el6):
https://bodhi.fedoraproject.org/updates/FEDORA-EPEL-2017-29f7b67071
Fedora Security Update FEDORA-EPEL-2017-95bf973a7d (Fedora EPEL 7,
wordpress-4.8.3-1.el7):
https://bodhi.fedoraproject.org/updates/FEDORA-EPEL-2017-95bf973a7d
WordPress 4.8.3 Release Notes:
https://wordpress.org/news/2017/10/wordpress-4-8-3-security-release/
(c) DFN-CERT Services GmbH, all rights reserved!
Die Weiterverbreitung ist mit Hinweis auf den Copyrightinhaber innerhalb der
eigenen Einrichtung erlaubt. Eine darüber hinausgehende Verbreitung bedarf
des schriftlichen Einverständnisses des Rechteinhabers.