May 27, 2005

Here we go again - another WordPress Update to fix a security vulnerability

Boy – this sure is starting to sound like a broken record. WordPress 1.5.1.2 has now been released to fix a security vulnerability.

According to the developers:

It has come to our attention that under certain circumstances there is a security vulnerability in WordPress that may be triggered if you’re running the default template. We were able to respond very quickly (under 40 minutes) and update the download to 1.5.1.2. You can upgrade by overwriting your old 1.5 files or if you would like to apply the fix manually it is relatively simple:

  1. Open the wp-includes/template-functions-category.php file in a text editor like Wordpad.
  2. Go to around line 103 where it says get_the_category_by_ID.
  3. Create a new line after that and paste in $cat_ID = (int) $cat_ID;

One note, even if the vulnerability was present in your blog, you would still be safe if your host ran mod_security on their servers. It is an Apache module which can provide very high-level protection against everything like the vulnerability above to comment spam. We will be updating the hosting page shortly to reflect which hosts there support mod_security or not.

So, if I understand what they’re saying correctly, the vulnerability only affects users who are running the default template…? Nonetheless, I’d go ahead and make the upgrade (or just do the manual fix) – never want to chance having a security hole. Oy.

Bookmark at:
    Bookmark Here we go again - another WordPress Update to fix a security vulnerability at del.icio.us    Digg Here we go again - another WordPress Update to fix a security vulnerability at Digg.com    Bookmark Here we go again - another WordPress Update to fix a security vulnerability at Spurl.net    Bookmark Here we go again - another WordPress Update to fix a security vulnerability at Simpy.com    Bookmark Here we go again - another WordPress Update to fix a security vulnerability at NewsVine    Blink this Here we go again - another WordPress Update to fix a security vulnerability at blinklist.com    Bookmark Here we go again - another WordPress Update to fix a security vulnerability at Furl.net    Bookmark Here we go again - another WordPress Update to fix a security vulnerability at reddit.com    Fark Here we go again - another WordPress Update to fix a security vulnerability at Fark.com    Bookmark Here we go again - another WordPress Update to fix a security vulnerability at YahooMyWeb
Filed under , , , by Emily from How to Blog.
Permalink • Print •  • Comment

Related posts

    Track this entry:

    Trackback url

    Cosmos

    Terms2tags:

    Comments

    WordPress 1.5.1.2

    Новая версия движка WordPress появилась на официальном сайте. В этой версии оказалась заделана дыра в безопасности, связанная со стандартным шаблоном. Команда разработчиков отреагировала достаточно быстро - и через 40 минут была опубликована новая верс…

    WordPress 1.5.1.2

    ????? ?????? ?????? WordPress ????????? ?? ??????????? ?????. ? ???? ?????? ????????? ???????? ???? ? ????????????, ????????? ?? ??????????? ????????. ??????? ????????????? ????????????? ?????????? ?????? - ? ????? 40 ????? ???? ???????????? ????? ????…

    June 5, 2005

    Angsuman Chakraborty said:

    Not to mention that in 1.5.1.2 pingback and trackback sending is broken.

    So the patch which was a fix(1.5.1.2) to a fix(1.5.1.1) to a fix (1.5.1) ( http://blog.taragana.com/index.php/archive/oh-no-yet-another-wordpress-fix-to-a-fix-to-a-fix/ ) needs another fix!

    I am not comfortable with the state of things here.

    August 23, 2005

    Neil said:

    Thanks for the info. This wordpress updating is getting a little tiring… oh, well… it’s free, for now….

    Leave a comment

    Made with WordPress and the Semiologic CMS | Customized by Emily Robbins