Wordpress rilascia l´update di sicurezza 3.3.2

Naviga SWZ: Home Page » News
News del 20 Aprile 12 Autore: Gianplugged
Wordpress rilascia l´update di sicurezza 3.3.2
WordPress ha rilasciato l´aggiornamento di sicurezza 3.3.2, che risolve numerose vulnerabilità delle precedenti release. In particolare, tre librerie esterne incluse in WordPress sono state aggiornate: Plupload, SWFUpload e SWFObject.

WordPress 3.3.2 risolve altre differenti bug, come dettagliato nelle note di rilascio, e l´aggiornamento è consigliato a tutti gli utenti.

Note di rilascio:

WordPress 3.3.2 is available now and is a security update for all previous versions.

Three external libraries included in WordPress received security updates:

Plupload (version 1.5.4), which WordPress uses for uploading media.
SWFUpload, which WordPress previously used for uploading media, and may still be in use by plugins.
SWFObject, which WordPress previously used to embed Flash content, and may still be in use by plugins and themes.
Thanks to Neal Poole and Nathan Partlan for responsibly disclosing the bugs in Plupload and SWFUpload, and Szymon
Gruszecki for a separate bug in SWFUpload.

WordPress 3.3.2 also addresses:

Limited privilege escalation where a site administrator could deactivate network-wide plugins when running a WordPress network under particular circumstances, disclosed by Jon Cave of our WordPress core security team, and Adam Backstrom.
Cross-site scripting vulnerability when making URLs clickable, by Jon Cave.
Cross-site scripting vulnerabilities in redirects after posting comments in older browsers, and when filtering URLs.

Thanks to Mauro Gentile for responsibly disclosing these issues to the security team.
These issues were fixed by the WordPress core security team. Five other bugs were also fixed in version 3.3.2. Consult the change log for more details.
Inserisci un commento sul forum Commenta la News sul Forum

Voto:

Categoria: P2P e Web

Licenza: Open Source

Dimensioni: 3.8 MB

La Community di SWZone.it

La community con le risposte che cerchi ! Partecipa é gratis !
Iscrizione ForumIscriviti al Forum

Newsletter

Vuoi ricevere tutti gli aggiornamenti di SWZone direttamente via mail ?
Iscrizione NewsletterIscriviti alla Newsletter

NOTIZIE CORRELATE