TEMP-0783347-555527

NameTEMP-0783347-555527
Descriptionfiles with invalid or unsafe names could be uploaded
SourceAutomatically generated temporary name. Not for external reference.
Debian Bugs783347

Vulnerable and fixed packages

The table below lists information on source packages.

Source PackageReleaseVersionStatus
wordpress (PTS)wheezy3.6.1+dfsg-1~deb7u10fixed
wheezy (security)3.6.1+dfsg-1~deb7u20fixed
jessie4.1+dfsg-1+deb8u15fixed
jessie (security)4.1+dfsg-1+deb8u16fixed
stretch4.7.5+dfsg-2+deb9u1fixed
stretch (security)4.7.5+dfsg-2+deb9u2fixed
buster, sid4.9.4+dfsg-1fixed

The information below is based on the following data on fixed versions.

PackageTypeReleaseFixed VersionUrgencyOriginDebian Bugs
wordpresssource(unstable)4.2+dfsg-1783347
wordpresssourcejessie4.1+dfsg-1+deb8u1
wordpresssourcesqueeze(not affected)
wordpresssourcewheezy(not affected)

Notes

[wheezy] - wordpress <not-affected> (File upload vulnerability only in WordPress 4.1 and higher)
[squeeze] - wordpress <not-affected> (File upload vulnerability only in WordPress 4.1 and higher)
https://wordpress.org/news/2015/04/wordpress-4-1-2/
http://www.openwall.com/lists/oss-security/2015/04/26/2
To be decided: http://www.openwall.com/lists/oss-security/2015/04/28/7
CVE Request: http://www.openwall.com/lists/oss-security/2015/06/10/11

Search for package or bug name: Reporting problems