=====================================================================
                                   CERT-Renater

                        Note d'Information No. 2010/VULN565
_____________________________________________________________________

DATE                      : 30/12/2010

HARDWARE PLATFORM(S)      : /

OPERATING SYSTEM(S)       : Systems running wordpress versions prior to 3.0.4.

======================================================================
http://wordpress.org/news/2010/12/3-0-4-update/
______________________________________________________________________

3.0.4 Important Security Update
Posted December 29, 2010 by Matt Mullenweg. Filed under Releases,Security.

Version 3.0.4 of WordPress, available immediately through the update page
in your dashboard or for download here, is a very important update to apply
to your sites as soon as possible because it fixes a core security bug in
our HTML sanitation library, called KSES. I would rate this release as “critical.”

I realize an update during the holidays is no fun, but this one is worth
putting down the eggnog for. In the spirit of the holidays, consider
helping your friends as well.

If you are a security researcher, we’d appreciate you taking a look over
this changeset as well to review our update. We’ve given it a lot of thought
and review but since this is so core we want as many brains on it as possible.
Thanks to Mauro Gentile and Jon Cave (duck_) who discovered and alerted
us to these XSS vulnerabilities first.


======================================================================

          =========================================================
          Les serveurs de référence du CERT-Renater
          http://www.urec.fr/securite
          http://www.cru.fr/securite
          http://www.renater.fr
          =========================================================
          + CERT-RENATER          | tel : 01-53-94-20-44          +
          + 23 - 25 Rue Daviel    | fax : 01-53-94-20-41          +
          + 75013 Paris           | email: certsvp@renater.fr     +
          =========================================================


