09

WordPress 官方开发博客今早发出了关于 WordPress 2.6.2 发布 的消息,以下是翻译:

Stefan Esser 近日向开发者们发出关于 SQL Column Truncation 的危险性和 mt_rand() 函数的缺陷 的警告。 在他的帮助下我们着手解决了这些问题,现在发布 WordPress 2.6.2。如果您的博客允许自由注册用户,请务必升级到新版本。在自由注册开放的前提下, WordPress 2.6.1 以及更早的版本都存在漏洞,可能会被通过一个特殊的用户名将其他用户的密码重新设定为随机密码。该随机密码对于攻击者是不可知的,因此这是一个安全困扰,但还不算一个漏洞利用。不过,该攻击方式可根据 mt_rand() 函数中随机数传递过程的一个缺陷来预测随机密码。 Stefan Esser 将在不久后发布整个攻击过程的详细资料。该攻击虽不易实现,但它促使我们推荐各位升级到 2.6.2 。

PHP 的其他应用程序 同样容易遭受该类攻击。请获取Suhosin 的最新版本以保障您的PHP应用程序安全性。如果您已经升级到最新 Suhosin ,您现有的 WordPress 将不会受此漏洞利用影响。当然,如果您的博客开放自由注册,您依然需要升级到 2.6.2 ,以防止密码被随机化。

2.6.2 还包含了一些 bug 修正补丁,点击此处查看WordPress 2.6.2 所有更新以及更新文件列表

以下是原文 WordPress 2.6.2 release

By Ryan. Filed under Releases, Security.

Stefan Esser recently warned developers of the dangers of SQL Column Truncation and the weakness of mt_rand().  With his help we worked around these problems and are now releasing WordPress 2.6.2.  If you allow open registration on your blog, you should definitely upgrade.  With open registration enabled, it is possible in WordPress versions 2.6.1 and earlier to craft a username such that it will allow resetting another user’s password to a randomly generated password.  The randomly generated password is not disclosed to the attacker, so this problem by itself is annoying but not a security exploit.  However, this attack coupled with a weakness in the random number seeding in mt_rand() could be used to predict the randomly generated password.  Stefan Esser will release details of the complete attack shortly.  The attack is difficult to accomplish,  but its mere possibility means we recommend upgrading to 2.6.2.

Other PHP apps are susceptible to this class of attack.  To protect all of your apps, grab the latest version of Suhosin.  If you’ve already updated Suhosin, your existing WordPress install is already protected from the full exploit.  You should still upgrade to 2.6.2 if you allow open user registration so as to prevent the possibility of passwords being randomized.

2.6.2 also contains a handful of bug fixes.  Check out the full changeset and list of changed files.

————————

本文将跟进WordPress 2.6.2 的汉化消息~。

————————

WordPress 2.6.2 中文版-修正版(zip格式)

http://wordpresschina.googlecode.com/files/wordpress.262.chs.fix.zip

WordPress 2.6.2 中文版-修正版(gz格式)

http://wordpresschina.googlecode.com/files/wordpress.262.chs.tar.gz

From: http://wpchina.org/wordpress-262-chinese-version-has-a-problem-347/

————————————-

这里已经出现漏洞利用了~,看起来必须更新了啊~!!!

http://www.jokworld.cn/wordpress-loudong.kao

你在使用下面这些服务吗?那就推一下本文吧:
QQ书签 | Google书签 | 收客 | Del.icio.us | 百度搜藏 | Diglog | 我挖网 | 鲜果

一个人在聊 “WordPress 2.6.2 发布了,有一个重要安全更新. update released”

  1. 徐恒 Says:

    看来确实需要升级一下了

随便聊一聊

SEO Powered by Platinum SEO from Techblissonline