infinix x yugatech

Important Security fix on WordPress 2.5.1

Listen to article

A new WordPress release is just out on version 2.5.1 which fixes tons of bugs and a patch to a very important security vulnerability specifically if your blog is open to user registration. Those on WordPress is strongly encouraged to upgrade.

If you download the entire WordPress 2.5.1 release, you will be getting over 70 other fixes. This update focuses on fixing the most annoying bugs and improving performance. Here are some of the highlights:

  • Performance improvements for the Dashboard, Write Post, and Edit Comments pages.
  • Better performance for those who have many categories
  • Media Uploader fixes
  • An upgrade to TinyMCE 3.0.7
  • Widget Administration fixes
  • Various usability improvements
  • Layout fixes for IE

http://www.yugatech.com/blog/wp-admin/post-new.php

Most importantly, a security fix is included in this update:

An attacker, who is able to register a specially crafted username on a WordPress 2.5 installation, is able to generate authentication cookies for other chosen accounts.

This vulnerability exists because it is possible to modify authentication cookies without invalidating the cryptographic integrity protection.

If a WordPress blog is configured to freely permit account creation, a remote attacker can gain WordPress-administrator access and then elevate this to arbitrary code execution as the web server user.

If you’ve just updated to WP 2.5, you need to get the update to fix this risky security hole.

React to this article:
Written by
Abe Olandres

Abe Olandres

Editor-in-chief

Abe is the founder and Editor-in-Chief of YugaTech with over 20 years of experience in the technology industry. He is one of the pioneers of blogging in the country and is considered by many as the Father of Tech Blogging in the Philippines.

View all posts by Abe Olandres →

10 Comments

AC
Acne Health Remedy · · 16 years ago

desktop computers with Intel i5 cores are the best because they are very very fast and great for multitasking “.*


Reply
AB
Abe Olandres Editor-in-chief · 18 years ago

@sylv3rblade, thanks for the tip. Got it fixed on Feedburner’s side.


Reply
PE
penstalker · 18 years ago

aww. So WP 2.5 has a major security risk. Gotta upgrade asap.


Reply
SY
sylv3rblade · 18 years ago

ouch. hmm just upgraded.

Umm just noticed. Sir Abe. Your main feed doesn’t seem to be working: http://feeds.feedburner.com/yugatech/LjSi
It’s empty.


Reply

Leave a Reply

Loading next article...