=====================================================================
                                    CERT-Renater

                         Note d'Information No. 2011/VULN295
_____________________________________________________________________

DATE                      : 06/04/2011

HARDWARE PLATFORM(S)      : /

OPERATING SYSTEM(S)       : Systems running WordPress versions 3 prior to 3.1.1.

======================================================================
http://wordpress.org/news/2011/04/wordpress-3-1-1/
______________________________________________________________________


WordPress News

WordPress 3.1.1

Posted April 5, 2011 by Ryan Boren. Filed under Releases,Security.

WordPress 3.1.1 is now available. This maintenance and security release
fixes almost thirty issues in 3.1, including:

     * Some security hardening to media uploads
     * Performance improvements
     * Fixes for IIS6 support
     * Fixes for taxonomy and PATHINFO (/index.php/) permalinks
     * Fixes for various query and taxonomy edge cases that caused some
plugin compatibility issues

Version 3.1.1 also addresses three security issues discovered by WordPress
core developers Jon Cave and Peter Westwood, of our security team. The first
hardens CSRF prevention in the media uploader. The second avoids a PHP crash
in certain environments when handling devilishly devised links in comments,
and the third addresses an XSS flaw.

We suggest you update to 3.1.1 promptly. Download 3.1.1 or update automatically
from the Dashboard → Updates menu in your site’s admin area.

Our release haiku:

Only the geeks know
What half this stuff even means
Don’t worry — update

======================================================================

           =========================================================
           Les serveurs de référence du CERT-Renater
           http://www.urec.fr/securite
           http://www.cru.fr/securite
           http://www.renater.fr
           =========================================================
           + CERT-RENATER          | tel : 01-53-94-20-44          +
           + 23 - 25 Rue Daviel    | fax : 01-53-94-20-41          +
           + 75013 Paris           | email: certsvp@renater.fr     +
           =========================================================




