March 3, 2007

WordPress 2.1.1 Dangerous - Upgrade Now!

WordPress 2.1.1 Download Is Dangerous!

I just got this from the WordPress blog and I strongly suggest you read it if you've downloaded WordPress 2.1.1 within the last 3-4 days or so.

WordPress 2.1.1 Dangerous, Upgrade

"Long story short: If you downloaded WordPress 2.1.1 within the past 3-4 days, your files may include a security exploit that was added by a cracker, and you should upgrade all of your files to 2.1.2 immediately.

Longer explanation: This morning we received a note to our security mailing address about unusual and highly exploitable code in WordPress. The issue was investigated, and it appeared that the 2.1.1 download had been modified from its original code. We took the website down immediately to investigate what happened.

It was determined that a cracker had gained user-level access to one of the servers that powers wordpress.org, and had used that access to modify the download file. We have locked down that server for further forensics, but at this time it appears that the 2.1.1 download was the only thing touched by the attack. They modified two files in WP to include code that would allow for remote PHP execution."

Secure Your WordPress Blog

WordPress also states, "If your blog is running 2.1.1, please upgrade immediately and do a full overwrite of your old files, especially those in wp-includes. Check out your friends blogs and if any of them are running 2.1.1 drop them a note and, if you can, pitch in and help them with the upgrade."

The latest WordPress download is here: New version 2.1.2

No comments:

Post a Comment

Thanks for visiting the Aaron Cook Dot Com™ blog! Please leave your awesome comment below! :)

Shine on,
Aaron