~ubuntu-security/ubuntu-cve-tracker/master

« back to all changes in this revision

Viewing changes to retired/CVE-2010-5106

  • Committer: Steve Beattie
  • Date: 2019-02-19 06:18:27 UTC
  • Revision ID: sbeattie@ubuntu.com-20190219061827-oh57fzcfc1u9dlfk
The ubuntu-cve-tracker project has been converted to git.

Please use 'git clone https://git.launchpad.net/ubuntu-cve-tracker' to
get the converted tree.

Show diffs side-by-side

added added

removed removed

Lines of Context:
1
 
Candidate: CVE-2010-5106
2
 
PublicDate: 2012-09-14
3
 
References:
4
 
 https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2010-5106
5
 
 http://openwall.com/lists/oss-security/2012/09/14/10
6
 
 http://core.trac.wordpress.org/changeset/16803
7
 
 http://codex.wordpress.org/Version_3.0.3
8
 
Description:
9
 
 The XML-RPC remote publishing interface in xmlrpc.php in WordPress before
10
 
 3.0.3 does not properly check capabilities, which allows remote
11
 
 authenticated users to bypass intended access restrictions, and publish,
12
 
 edit, or delete posts, by leveraging the Author or Contributor role.
13
 
Ubuntu-Description:
14
 
Notes:
15
 
Bugs:
16
 
Priority: medium
17
 
Discovered-by:
18
 
Assigned-to:
19
 
 
20
 
Patches_wordpress:
21
 
upstream_wordpress: released (3.0.3)
22
 
hardy_wordpress: ignored (reached end-of-life)
23
 
lucid_wordpress: ignored (reached end-of-life)
24
 
natty_wordpress: not-affected (3.0.5+dfsg-1ubuntu1)
25
 
oneiric_wordpress: not-affected
26
 
precise_wordpress: not-affected
27
 
quantal_wordpress: not-affected
28
 
raring_wordpress: not-affected
29
 
saucy_wordpress: not-affected
30
 
devel_wordpress: not-affected