Candidate: CVE-2012-4448 PublicDate: 2012-09-28 21:55:00 UTC References: https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2012-4448 http://www.openwall.com/lists/oss-security/2012/09/25/15 http://packetstormsecurity.org/files/116785/WordPress-3.4.2-Cross-Site-Request-Forgery.html Description: Cross-site request forgery (CSRF) vulnerability in wp-admin/index.php in WordPress 3.4.2 allows remote attackers to hijack the authentication of administrators for requests that modify an RSS URL via a dashboard_incoming_links edit action. Ubuntu-Description: Notes: Bugs: https://bugzilla.redhat.com/show_bug.cgi?id=860261 https://bugs.gentoo.org/show_bug.cgi?id=436198 Priority: medium Discovered-by: Assigned-to: CVSS: Patches_wordpress: upstream_wordpress: released (3.5.1+dfsg-2) hardy_wordpress: ignored (reached end-of-life) lucid_wordpress: ignored (reached end-of-life) natty_wordpress: ignored (reached end-of-life) oneiric_wordpress: ignored (reached end-of-life) precise_wordpress: ignored (reached end-of-life) precise/esm_wordpress: DNE (precise was needed) quantal_wordpress: ignored (reached end-of-life) raring_wordpress: ignored (reached end-of-life) saucy_wordpress: ignored (reached end-of-life) trusty_wordpress: not-affected (3.8.2+dfsg-1ubuntu0.1) trusty/esm_wordpress: DNE (trusty was not-affected [3.8.2+dfsg-1ubuntu0.1]) utopic_wordpress: ignored (reached end-of-life) vivid_wordpress: ignored (reached end-of-life) vivid/stable-phone-overlay_wordpress: DNE vivid/ubuntu-core_wordpress: DNE wily_wordpress: ignored (reached end-of-life) xenial_wordpress: not-affected (4.4.2+dfsg-1ubuntu1) yakkety_wordpress: ignored (reached end-of-life) zesty_wordpress: ignored (reached end-of-life) artful_wordpress: ignored (reached end-of-life) bionic_wordpress: not-affected (4.9.5+dfsg1-1) devel_wordpress: not-affected (4.9.7+dfsg1-1)