CVE-2007-0109

Publication date 9 January 2007

Last updated 24 July 2024


Ubuntu priority

wp-login.php in WordPress 2.0.5 and earlier displays different error messages if a user exists or not, which allows remote attackers to obtain sensitive information and facilitates brute force attacks.

Status

No maintained releases are affected by this CVE.

Package Ubuntu Release Status
wordpress 9.10 karmic
Not affected
9.04 jaunty
Not affected
8.10 intrepid
Not affected
8.04 LTS hardy
Not affected
7.10 gutsy
Not affected
7.04 feisty
Not affected
6.10 edgy Ignored end of life, was needed
6.06 LTS dapper Ignored end of life