Spotlight | Reviews | Current Issue | Newsletter | Subscribe | Contact |
Departments

user friendly

  linuxpromagazine.com » Online » News » WordPress 2.6.2 released for security reasons  

Print this page. Recommend
Slashdot it! Delicious Digg

WordPress 2.6.2 released for security reasons

Free blog software WordPress notifies of a security update in its 2.6.2 version.

The WordPress security breaches were discoverd by Stefan Esser. They are based partly on SQL column truncation and partly on the weakness of the mt_rand() function. These breaches are especially noticeable if open registration is allowed on the blog. An immediate WordPress upgrade is recommended for such blogs.

As the developers make clear in their announcement, it is possible in WordPress to reset another user's password. Taken alone this may be a mere annoyance to users, but combined with the weakness of the mt_rand() function there is a risk that the randomly generated password can be predicted. The discoverer of this security breach will release details soon. Possible other PHP applications are susceptible, according to the WordPress Blog. The project recommends a patch, but certainly an upgrade to 2.6.2 in case open user registration is enabled. The upgrade also includes a number of bug fixes.

(Ulrich Bantle)

Comments


Print this page. Recommend
Slashdot it! Delicious Digg
Wherever you go...

...Linux Magazine goes with you!

Check out the advantages of a Digital Subscription:

  • Access articles by downloading PDFs,
  • find the Linux solutions you need with an easy keyword search,
  • maintain your own paperless archive...

more...

 

In the US and Canada, Linux Magazine is known as Linux Pro Magazine.
Entire contents © 2008 [Linux New Media USA, LLC]
Linux New Media web sites:
North America: [Linux Pro Magazine]
UK/Worldwide: [Linux Magazine]
Germany: [Linux-Magazin] [LinuxUser] [EasyLinux] [Linux-Community] [Linux-Nachrichten] [Linux Events]
Eastern Europe: [Linux Magazine Poland] [Linux Community Poland] [Darmowe Programy Poland] [Open Source DVD Poland] [Linux Magazin Romania]
International: [Linux Magazine Brazil] [Linux Magazine Spanish]
Corporate: [Linux New Media AG]