6.8

CVE-2014-9037

Wordpress Core < 4.0.1 - Hash Collision

WordPress before 3.7.5, 3.8.x before 3.8.5, 3.9.x before 3.9.3, and 4.x before 4.0.1 might allow remote attackers to obtain access to an account idle since 2008 by leveraging an improper PHP dynamic type comparison for an MD5 hash.
Mögliche Gegenmaßnahme
WordPress: Update to one of the following versions, or a newer patched version: 3.7.5, 3.8.5, 3.9.3, 4.0.1
Daten sind bereitgestellt durch National Vulnerability Database (NVD)
Mageia Project ≫ Mageia Version 3
Mageia Project ≫ Mageia Version 4
Wordpress ≫ Wordpress Version <= 3.7.4
Wordpress ≫ Wordpress Version 3.8
Wordpress ≫ Wordpress Version 3.8.1
Wordpress ≫ Wordpress Version 3.8.2
Wordpress ≫ Wordpress Version 3.8.3
Wordpress ≫ Wordpress Version 3.8.4
Wordpress ≫ Wordpress Version 3.9
Wordpress ≫ Wordpress Version 3.9.1
Wordpress ≫ Wordpress Version 3.9.2
Wordpress ≫ Wordpress Version 4.0
Debian ≫ Debian Linux Version 7.0
Debian ≫ Debian Linux Version 8.0
Weitere Schwachstelleninformationen
SystemWordPress Core
≫
Produkt WordPress
Version [*, 3.7)
Version 3.7-3.7.4
Version 3.8-3.8.4
Version 3.9-3.9.2
Version 4.0
Zu dieser CVE wurde keine Warnung gefunden.
EPSS Metriken
Typ Quelle Score Percentile
EPSS FIRST.org 2.57% 0.831
CVSS Metriken
Quelle Base Score Exploit Score Impact Score Vector String
NIST 6.8 8.6 6.4
AV:N/AC:M/Au:N/C:P/I:P/A:P
Es wurden noch keine Informationen zu CWE veröffentlicht.
http://advisories.mageia.org/MGASA-2014-0493.html
http://openwall.com/lists/oss-security/2014/11/25/12
http://www.debian.org/security/2014/dsa-3085
http://www.mandriva.com/security/advisories?name=MDVSA-2014:233
http://www.securitytracker.com/id/1031243
https://wordpress.org/news/2014/11/wordpress-4-0-1/
Patch
Vendor Advisory
https://www.wordfence.com/threat-intel/vulnerabilities/id/05873114-ceed-404c-9cc2-d85aa92ef6f3
Third Party Advisory