Summary
The remote host is missing updates announced in
advisory GLSA 200703-23.
Solution
Due to the numerous recently discovered vulnerabilities in WordPress, this package has been masked in the portage tree. All WordPress users are advised to unmerge it.
# emerge --unmerge 'www-apps/wordpress'
http://www.securityspace.com/smysecure/catid.html?in=GLSA%20200703-23 http://bugs.gentoo.org/show_bug.cgi?id=168529
http://secunia.com/advisories/24430/
Insight
Wordpress contains several cross-site scripting, cross-site request forgery and information leak vulnerabilities.
Severity
Classification
-
CVE CVE-2007-1049, CVE-2007-1230, CVE-2007-1244, CVE-2007-1409 -
CVSS Base Score: 6.8
AV:N/AC:M/Au:N/C:P/I:P/A:P
Related Vulnerabilities