[wp-trac] [WordPress Trac] #39309: Secure WordPress Against Infrastructure Attacks

WordPress Trac noreply at wordpress.org
Thu Apr 4 16:07:30 UTC 2019


#39309: Secure WordPress Against Infrastructure Attacks
------------------------------------------+-----------------------
 Reporter:  paragoninitiativeenterprises  |       Owner:  pento
     Type:  task (blessed)                |      Status:  assigned
 Priority:  normal                        |   Milestone:  5.2
Component:  Upgrade/Install               |     Version:  4.8
 Severity:  critical                      |  Resolution:
 Keywords:  has-patch                     |     Focuses:
------------------------------------------+-----------------------

Comment (by paragoninitiativeenterprises):

 > After reviewing the error debugging included, it looks like we've got a
 few clients failing to verify signatures, but the reason isn't jumping out
 at me straight away.

 Could you forward some details about this to security at paragonie.com at
 your earliest convenience? If there's a platform-specific bug affecting
 Ed25519 signature verification, it probably needs to be fixed inside
 sodium_compat.

-- 
Ticket URL: <https://core.trac.wordpress.org/ticket/39309#comment:70>
WordPress Trac <https://core.trac.wordpress.org/>
WordPress publishing platform


More information about the wp-trac mailing list