WordPress 'is_serialized()' Function Arbitrary Code Execution Vulnerability
BID:62345
Info
WordPress 'is_serialized()' Function Arbitrary Code Execution Vulnerability
| Bugtraq ID: | 62345 |
| Class: | Input Validation Error |
| CVE: |
CVE-2013-4338 |
| Remote: | Yes |
| Local: | No |
| Published: | Sep 10 2013 12:00AM |
| Updated: | Apr 13 2015 08:55PM |
| Credit: | Tom Van Goethem |
| Vulnerable: | |
| Not Vulnerable: | |
Discussion
WordPress 'is_serialized()' Function Arbitrary Code Execution Vulnerability
WordPress is prone to an arbitrary code-execution vulnerability.
An attacker can exploit this issue to execute arbitrary code with the privileges of the user running the affected application.
The issue is fixed in WordPress 3.6.1.
WordPress is prone to an arbitrary code-execution vulnerability.
An attacker can exploit this issue to execute arbitrary code with the privileges of the user running the affected application.
The issue is fixed in WordPress 3.6.1.
Solution / Fix
WordPress 'is_serialized()' Function Arbitrary Code Execution Vulnerability
Solution:
Updates are available. Please see the references or vendor advisory for more information.
Mandriva Business Server 1 X86 64
Solution:
Updates are available. Please see the references or vendor advisory for more information.
Mandriva Business Server 1 X86 64
-
Mandriva php-phpmailer-5.2.7-0.20130917.1.mbs1.noarch.rpm
http://www.mandriva.com/en/downloads/ -
Mandriva wordpress-3.6.1-1.mbs1.noarch.rpm
http://www.mandriva.com/en/downloads/