[CVE-2007-6013] Authentication cookies easily derivable from password hash

Bug #172440 reported by William Grant
270
Affects Status Importance Assigned to Milestone
WordPress
Fix Released
Unknown
wordpress (Debian)
Fix Released
Unknown
wordpress (Ubuntu)
Fix Released
Medium
Emanuele Gentili
Dapper
Won't Fix
Undecided
Unassigned
Feisty
Won't Fix
Undecided
Unassigned
Gutsy
Won't Fix
Undecided
Emanuele Gentili

Bug Description

Binary package hint: wordpress

Wordpress 1.5 to 2.3.1 uses cookie values based on the MD5 hash of a password MD5 hash, which allows attackers to bypass authentication by obtaining the MD5 hash from the user database, then generating the authentication cookie from that hash.

Combined with the prevalence of SQL injection in WordPress, this could be an issue. Otherwise it's fairly unimportant.

CVE References

William Grant (wgrant)
Changed in wordpress:
importance: Undecided → Medium
status: New → Confirmed
Changed in wordpress:
status: Unknown → New
Changed in wordpress:
status: New → Confirmed
Changed in wordpress:
status: Unknown → New
Revision history for this message
Emanuele Gentili (emgent) wrote :

diff for gutsy is ready.

Revision history for this message
Emanuele Gentili (emgent) wrote :

wrong post/patch, redirect to open CVE-2007-6318

Changed in wordpress:
status: Confirmed → Fix Released
Changed in wordpress:
assignee: nobody → emgent
Revision history for this message
Emanuele Gentili (emgent) wrote :

 wordpress | 2.0.2-2 | dapper/universe | source, all
 wordpress | 2.0.4-2 | edgy/universe | source, all
 wordpress | 2.1.0-1~edgy1 | edgy-backports/universe | source, all
 wordpress | 2.1.2-1ubuntu1~dapper1 | dapper-backports/universe | source, all
 wordpress | 2.1.3-1ubuntu1 | feisty/universe | source, all
 wordpress | 2.1.3-1ubuntu1.1 | feisty-security/universe | source, all
 wordpress | 2.1.3-1ubuntu1.1 | feisty-updates/universe | source, all
 wordpress | 2.2.2-1ubuntu1 | gutsy/universe | source, all
 wordpress | 2.2.2-1ubuntu1.3 | gutsy-security/universe | source, all
 wordpress | 2.2.2-1ubuntu1.3 | gutsy-updates/universe | source, all
 wordpress | 2.3.3-1ubuntu1 | hardy/universe | source, all

System Affected:
Wordpress 1.5 -- 2.3.1

Ubuntu status:
Hardy not affected.
Gutsy, Feisty, Edgy, Dapper affected.

Changed in wordpress:
status: New → Fix Committed
Changed in wordpress:
status: Fix Committed → Fix Released
William Grant (wgrant)
Changed in wordpress:
status: Confirmed → Fix Released
Revision history for this message
Emanuele Gentili (emgent) wrote :

@ScottK: what do you think about the possibility to backport it?

Changed in wordpress:
assignee: nobody → emgent
status: New → Confirmed
Revision history for this message
Hew (hew) wrote :

Ubuntu Feisty Fawn is no longer supported, so a SRU will not be issued for this release. Marking Feisty as Won't Fix.

Changed in wordpress:
status: New → Won't Fix
Revision history for this message
Sergio Zanchetta (primes2h) wrote :

The 18 month support period for Gutsy Gibbon 7.10 has reached its end of life -
http://www.ubuntu.com/news/ubuntu-7.10-eol . As a result, we are closing the
Gutsy task.

Changed in wordpress (Ubuntu Gutsy):
status: Confirmed → Won't Fix
Revision history for this message
Jamie Strandboge (jdstrand) wrote :

Thank you for reporting this bug to Ubuntu. dapper has reached EOL
(End of Life) and is no longer supported. As a result, this bug
against dapper is being marked "Won't Fix". Please see
https://wiki.ubuntu.com/Releases for currently supported Ubuntu
releases.

Please feel free to report any other bugs you may find.

Changed in wordpress (Ubuntu Dapper):
status: New → Won't Fix
To post a comment you must log in.
This report contains Public Security information  
Everyone can see this security related information.

Duplicates of this bug

Other bug subscribers

Remote bug watches

Bug watches keep track of this bug in other bug trackers.