FreeBSD VuXML: Documenting security issues in FreeBSD and the FreeBSD Ports Collection

CVE-2013-4339

This CVE name corresponds to:

Entered Topic
2013-10-19 wordpress -- multiple vulnerabilities

The following information is adapted from the Common Vulnerabilities and Exposures (CVE) project. CVE and the CVE logo are trademarks of The MITRE Corporation. CVE content is Copyright 2005, The MITRE Corporation.

Details

Type Candidate
Name CVE-2013-4339
Phase Assigned(20130612)

Description

WordPress before 3.6.1 does not properly validate URLs before use in an HTTP redirect, which allows remote attackers to bypass intended redirection restrictions via a crafted string.

References

Source Reference
FULLDISC 20131219 URL Redirector Abuse and XSS vulnerabilities in WordPress
CONFIRM http://codex.wordpress.org/Version_3.6.1
CONFIRM http://core.trac.wordpress.org/changeset/25323
CONFIRM http://core.trac.wordpress.org/changeset/25324
CONFIRM http://wordpress.org/news/2013/09/wordpress-3-6-1/
DEBIAN DSA-2757
FEDORA FEDORA-2013-16855
FEDORA FEDORA-2013-16895
FEDORA FEDORA-2013-16925
OSVDB 101181