CVE-2013-2203

NameCVE-2013-2203
DescriptionWordPress before 3.5.2, when the uploads directory forbids write access, allows remote attackers to obtain sensitive information via an invalid upload request, which reveals the absolute path in an XMLHttpRequest error message.
SourceCVE (at NVD; CERT, LWN, oss-sec, fulldisc, bugtraq, EDB, Metasploit, Red Hat, Ubuntu, Gentoo, SuSE, Mageia, GitHub code/issues, web search, more)
ReferencesDSA-2718-1
NVD severitymedium (attack range: remote)
Debian Bugs713947

Vulnerable and fixed packages

The table below lists information on source packages.

Source PackageReleaseVersionStatus
wordpress (PTS)wheezy3.6.1+dfsg-1~deb7u10fixed
wheezy (security)3.6.1+dfsg-1~deb7u12fixed
jessie4.1+dfsg-1+deb8u9fixed
jessie (security)4.1+dfsg-1+deb8u11fixed
stretch4.6.1+dfsg-2fixed
sid4.7+dfsg-1fixed

The information below is based on the following data on fixed versions.

PackageTypeReleaseFixed VersionUrgencyOriginDebian Bugs
wordpresssource(unstable)3.5.2+dfsg-1medium713947
wordpresssourcesqueeze3.5.2+dfsg-1~deb6u1mediumDSA-2718-1
wordpresssourcewheezy3.5.2+dfsg-1~deb7u1mediumDSA-2718-1

Search for package or bug name: Reporting problems