CVE-2017-5493

NameCVE-2017-5493
Descriptionwp-includes/ms-functions.php in the Multisite WordPress API in WordPress before 4.7.1 does not properly choose random numbers for keys, which makes it easier for remote attackers to bypass intended access restrictions via a crafted (1) site signup or (2) user signup.
SourceCVE (at NVD; CERT, LWN, oss-sec, fulldisc, bugtraq, EDB, Metasploit, Red Hat, Ubuntu, Gentoo, SuSE, Mageia, GitHub code/issues, web search, more)
ReferencesDLA-813-1, DSA-3779-1
NVD severitymedium (attack range: remote)
Debian Bugs851310

Vulnerable and fixed packages

The table below lists information on source packages.

Source PackageReleaseVersionStatus
wordpress (PTS)wheezy3.6.1+dfsg-1~deb7u10vulnerable
wheezy (security)3.6.1+dfsg-1~deb7u19fixed
jessie4.1+dfsg-1+deb8u14fixed
jessie (security)4.1+dfsg-1+deb8u15fixed
stretch4.7.5+dfsg-2fixed
stretch (security)4.7.5+dfsg-2+deb9u1fixed
buster, sid4.8.3+dfsg-1fixed

The information below is based on the following data on fixed versions.

PackageTypeReleaseFixed VersionUrgencyOriginDebian Bugs
wordpresssource(unstable)4.7.1+dfsg-1medium851310
wordpresssourcejessie4.1+dfsg-1+deb8u12mediumDSA-3779-1
wordpresssourcewheezy3.6.1+dfsg-1~deb7u13mediumDLA-813-1

Notes

http://www.openwall.com/lists/oss-security/2017/01/14/1
https://wpvulndb.com/vulnerabilities/8721
https://github.com/WordPress/WordPress/commit/cea9e2dc62abf777e06b12ec4ad9d1aaa49b29f4

Search for package or bug name: Reporting problems