Candidate: CVE-2012-3385 PublicDate: 2012-07-22 17:55:00 UTC References: https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2012-3385 http://www.openwall.com/lists/oss-security/2012/07/02/1 http://www.openwall.com/lists/oss-security/2012/07/08/1 Description: WordPress before 3.4.1 does not properly restrict access to post contents such as private or draft posts, which allows remote authors or contributors to obtain sensitive information via unknown vectors. Ubuntu-Description: Notes: Bugs: http://bugs.debian.org/cgi-bin/bugreport.cgi?bug=680721 Priority: low Discovered-by: Assigned-to: CVSS: Patches_wordpress: upstream_wordpress: released (3.4.1+dfsg-1) hardy_wordpress: ignored (reached end-of-life) lucid_wordpress: ignored (reached end-of-life) natty_wordpress: ignored (reached end-of-life) oneiric_wordpress: ignored (reached end-of-life) precise_wordpress: ignored (reached end-of-life) precise/esm_wordpress: DNE (precise was needs-triage) quantal_wordpress: not-affected (3.4.1+dfsg-1) raring_wordpress: not-affected (3.4.1+dfsg-1) saucy_wordpress: not-affected (3.4.1+dfsg-1) trusty_wordpress: not-affected (3.4.1+dfsg-1) trusty/esm_wordpress: DNE (trusty was not-affected [3.4.1+dfsg-1]) utopic_wordpress: not-affected (3.4.1+dfsg-1) vivid_wordpress: not-affected (3.4.1+dfsg-1) vivid/stable-phone-overlay_wordpress: DNE vivid/ubuntu-core_wordpress: DNE wily_wordpress: not-affected (3.4.1+dfsg-1) xenial_wordpress: not-affected (3.4.1+dfsg-1) yakkety_wordpress: not-affected (3.4.1+dfsg-1) zesty_wordpress: not-affected (3.4.1+dfsg-1) devel_wordpress: not-affected (3.4.1+dfsg-1)