
====================================================================

                             CERT-Renater

                 Note d'Information No. 2018/VULN130
_____________________________________________________________________

DATE                : 04/04/2018

HARDWARE PLATFORM(S): /

OPERATING SYSTEM(S): Systems running WordPress versions prior to 4.9.5.

=====================================================================
https://wordpress.org/news/2018/04/wordpress-4-9-5-security-and-maintenance-release/
_____________________________________________________________________

WordPress 4.9.5 Security and Maintenance Release
Posted April 3, 2018 by Aaron D. Campbell. Filed under Releases.


WordPress 4.9.5 is now available. This is a security and maintenance
release for all versions since WordPress 3.7. We strongly encourage you
to update your sites immediately.


WordPress versions 4.9.4 and earlier are affected by three security
issues. As part of the core team's ongoing commitment to security
hardening, the following fixes have been implemented in 4.9.5:


    Don't treat localhost as same host by default.
    Use safe redirects when redirecting the login page if SSL is forced.
    Make sure the version string is correctly escaped for use in
generator tags.


Thank you to the reporters of these issues for practicing ﻿coordinated
security disclosure: xknown of the WordPress Security Team, Nitin
Venkatesh (nitstorm), and Garth Mortensen of the WordPress Security
Team.


Twenty-five other bugs were fixed in WordPress 4.9.5. Particularly of
note were:


    The previous styles on caption shortcodes have been restored.
    Cropping on touch screen devices is now supported.
    A variety of strings such as error messages have been updated for
better clarity.
    The position of an attachment placeholder during uploads has been
fixed.
    Custom nonce functionality in the REST API JavaScript client has
been made consistent throughout the code base.
    Improved compatibility with PHP 7.2.


This post has more information about all of the issues fixed in 4.9.5
if you'd like to learn more.


Download WordPress 4.9.5 or venture over to Dashboard → Updates and
click "Update Now." Sites that support automatic background updates are
already beginning to update automatically.


Thank you to everyone who contributed to WordPress 4.9.5:

1265578519, Aaron Jorbin, Adam Silverstein, Alain Schlesser, alexgso,
Andrea Fercia, andrei0x309, antipole, Anwer AR, Birgir Erlendsson
(birgire), Blair jersyer, Brooke., Chetan Prajapati, codegrau,
conner_bw, David A. Kennedy, designsimply, Dion Hulse, Dominik
Schilling (ocean90), ElectricFeet, ericmeyer, FPCSJames, Garrett Hyder,
Gary Pendergast, Gennady Kovshenin, Henry Wright, Jb Audras, Jeffrey
Paul, Jip Moors, Joe McGill, Joen Asmussen, John Blackbourn,
johnpgreen, Junaid Ahmed, kristastevens, Konstantin Obenland, Laken
Hafner, Lance Willett, leemon, Mel Choyce, Mike Schroder, mrmadhat,
nandorsky, Nidhi Jain, Pascal Birchler, qcmiao, Rachel Baker, Rachel
Peter, RavanH, Samuel Wood (Otto), Sebastien SERRE, Sergey Biryukov,
Shital Marakana, Stephen Edgar, Tammie Lister, Thomas Vitale, Will
Kwon, and Yahil Madakiya.

==========================================================
+ CERT-RENATER          | tel : 01-53-94-20-44           +
+ 23 - 25 Rue Daviel    | fax : 01-53-94-20-41           +
+ 75013 Paris           | email: cert@support.renater.fr +
==========================================================



