Bug 1126065 (CVE-2019-8943) - VUL-1: CVE-2019-8943: wordpress: Path Traversal in wp_crop_image()
Summary: VUL-1: CVE-2019-8943: wordpress: Path Traversal in wp_crop_image()
Status: RESOLVED FIXED
Alias: CVE-2019-8943
Product: openSUSE Distribution
Classification: openSUSE
Component: Security (show other bugs)
Version: Leap 15.1
Hardware: Other Other
: P4 - Low : Minor (vote)
Target Milestone: ---
Assignee: Eric Schirra
QA Contact: Security Team bot
URL: https://smash.suse.de/issue/225052/
Whiteboard:
Keywords:
Depends on:
Blocks:
 
Reported: 2019-02-20 10:22 UTC by Robert Frohl
Modified: 2019-03-11 10:36 UTC (History)
0 users

See Also:
Found By: Security Response Team
Services Priority:
Business Priority:
Blocker: ---
Marketing QA Status: ---
IT Deployment: ---


Attachments

Note You need to log in before you can comment on or make changes to this bug.
Description Robert Frohl 2019-02-20 10:22:14 UTC
CVE-2019-8943

WordPress through 5.0.3 allows Path Traversal in wp_crop_image(). An attacker
(who has privileges to crop an image) can write the output image to an arbitrary
directory via a filename containing two image extensions and ../ sequences, such
as a filename ending with the .jpg?/../../file.jpg substring.

References:
http://web.nvd.nist.gov/view/vuln/detail?vulnId=CVE-2019-8943
https://blog.ripstech.com/2019/wordpress-image-remote-code-execution/
Comment 1 Eric Schirra 2019-02-25 07:59:45 UTC
Have done update to 5.1 in my home repo.
Before i push to devel i will test it.

But i don't know if CVE-2019-8943 is fixed, because it is plenty years
old and no entry found at wordpress itself.

See: https://www.securityfocus.com/bid/107089
Comment 2 Eric Schirra 2019-03-11 10:36:52 UTC
Was fixed in 5.1.