WordPress 2.6.2
Add commentsWordPress 2.6.2官方新闻:
Stefan Esser recently warned developers of the dangers of SQL Column Truncation and the weakness of mt_rand(). With his help we worked around these problems and are now releasing WordPress 2.6.2. If you allow open registration on your blog, you should definitely upgrade. With open registration enabled, it is possible in WordPress versions 2.6.1 and earlier to craft a username such that it will allow resetting another user’s password to a randomly generated password. The randomly generated password is not disclosed to the attacker, so this problem by itself is annoying but not a security exploit. However, this attack coupled with a weakness in the random number seeding in mt_rand() could be used to predict the randomly generated password. Stefan Esser will release details of the complete attack shortly. The attack is difficult to accomplish, but its mere possibility means we recommend upgrading to 2.6.2.
Other PHP apps are susceptible to this class of attack. To protect all of your apps, grab the latest version of Suhosin. If you’ve already updated Suhosin, your existing WordPress install is already protected from the full exploit. You should still upgrade to 2.6.2 if you allow open user registration so as to prevent the possibility of passwords being randomized.
2.6.2 also contains a handful of bug fixes. Check out the full changeset and list of changed files.
Related Posts
If you want to copy this post, please sign:Chenliang’s Blog
This post is linked: http://www.chinglishit.com/index.php/2008/09/09/wordpress-262/






10 Comments on “WordPress 2.6.2”
生是做网站的人。死是做网站的鬼。我的网站什么时候才有你网站的那么成功啊。羡慕中~~~不嫌弃的来个友情链接如何啊
博主的博客不错啊!我的网站什么时候才有你博客的那么成功啊。羡慕中~~~老大有没有论坛啊。。来个论坛做友情链接怎么样
Chen liang
Reply:
November 10th, 2008 at 12:22 pm
@搜易, 筹划中~~~,不知道做什么类型的,可能做编程相关的。到时友链你

文章不错啊!看完了给你留个脚印。顺便也留下我网站的链接。(*^__^*) 嘻嘻……没办法这年头做网站很难啊
Chen liang
Reply:
November 12th, 2008 at 7:56 am
@维修, 哈哈,是网赚难吧,现在做网站都是兴趣的事了。
^_^欢迎访问我的小站。泉州生活网的小站
看不懂啊
看不懂啊,好好
Chen liang
Reply:
December 19th, 2008 at 1:26 pm
@温州seo,
不错不错WordPress 2.6.2 | Chenliang's Blog

