Bug#784603: wordpress: Wordpress 4.2.2 critical security release

2015-05-28 Thread Craig Small
On Tue, May 26, 2015 at 06:43:15PM +0100, Rodrigo Campos wrote: Sorry to bother again, Craig. But any news on this? Bug opened #786886 which we will see if 4.1.5 gets in. - Craig -- Craig Small (@smallsees) http://enc.com.au/ csmall at : enc.com.au Debian GNU/Linux

Bug#784603: wordpress: Wordpress 4.2.2 critical security release

2015-05-26 Thread Rodrigo Campos
On Wed, May 20, 2015 at 10:08:44PM +1000, Craig Small wrote: On Mon, May 18, 2015 at 10:12:21AM +0200, Raphael Hertzog wrote: That's the general case. But with wordpress, the security team is rather open to integrate new upstream releases. We did it multiple times already. Let me ask them.

Bug#784603: wordpress: Wordpress 4.2.2 critical security release

2015-05-20 Thread Craig Small
On Mon, May 18, 2015 at 10:12:21AM +0200, Raphael Hertzog wrote: That's the general case. But with wordpress, the security team is rather open to integrate new upstream releases. We did it multiple times already. Let me ask them. I'd prefer to just use 4.1.5 in that case. - Craig -- Craig

Bug#784603: wordpress: Wordpress 4.2.2 critical security release

2015-05-18 Thread Raphael Hertzog
On Sat, 16 May 2015, Craig Small wrote: I mean, instead of using 4.2.x to extract the patches and backport, isn't it easier to extract them from 4.1.x for stable ? Or just do a new upstream release based on 4.1.5 ? The stable track is basically whatever version was there with security

Bug#784603: wordpress: Wordpress 4.2.2 critical security release

2015-05-18 Thread Rodrigo Campos
On Mon, May 18, 2015 at 10:12:21AM +0200, Raphael Hertzog wrote: On Sat, 16 May 2015, Craig Small wrote: I mean, instead of using 4.2.x to extract the patches and backport, isn't it easier to extract them from 4.1.x for stable ? Or just do a new upstream release based on 4.1.5 ?

Bug#784603: wordpress: Wordpress 4.2.2 critical security release

2015-05-15 Thread Craig Small
On Thu, May 07, 2015 at 05:31:03AM +0100, Rodrigo Campos wrote: A new Wordpress *critical* security release has been announced here: https://wordpress.org/news/2015/05/wordpress-4-2-2/ Can you please update and backport the patches to stable ? Also, let me know if you need help to backport,

Bug#784603: wordpress: Wordpress 4.2.2 critical security release

2015-05-15 Thread Rodrigo Campos
On Fri, May 15, 2015 at 09:08:28PM +1000, Craig Small wrote: On Thu, May 07, 2015 at 05:31:03AM +0100, Rodrigo Campos wrote: A new Wordpress *critical* security release has been announced here: https://wordpress.org/news/2015/05/wordpress-4-2-2/ Can you please update and backport the

Bug#784603: wordpress: Wordpress 4.2.2 critical security release

2015-05-15 Thread Rodrigo Campos
On Fri, May 15, 2015 at 02:35:45PM +0100, Rodrigo Campos wrote: On Fri, May 15, 2015 at 09:08:28PM +1000, Craig Small wrote: On Thu, May 07, 2015 at 05:31:03AM +0100, Rodrigo Campos wrote: A new Wordpress *critical* security release has been announced here:

Bug#784603: wordpress: Wordpress 4.2.2 critical security release

2015-05-15 Thread Craig Small
On Fri, May 15, 2015 at 03:09:35PM +0100, Rodrigo Campos wrote: doing things quite different. And doing this code reorganization would have fixed the XSS bug fixed in 4.2.1, but requires more time and test, so 4.2.1 was released and then 4.2.2 improved things. But, no idea, just thinking out

Bug#784603: wordpress: Wordpress 4.2.2 critical security release

2015-05-06 Thread Rodrigo Campos
Source: wordpress Version: 4.1+dfsg-1+deb8u1 Severity: important Dear Maintainer, A new Wordpress *critical* security release has been announced here: https://wordpress.org/news/2015/05/wordpress-4-2-2/ Can you please update and backport the patches to stable ? Also, let me know if you need