Bug#770425: Fixes for debian stable ?

2014-12-03 Thread Rodrigo Campos
On Wed, Dec 03, 2014 at 05:58:11PM +1100, Craig Small wrote:
 On Tue, Dec 02, 2014 at 02:17:37PM +, Rodrigo Campos wrote:
  The upstream release was on Nov 20, it's been almost 2 weeks and the bug 
  seem
  kind of serious. Any chance to do a quick fix and then continue to discuss
  changing wordpress version in stable ? Or any ETA on when the fixes will 
  come to
  stable ?
 The stable fix is being uploaded to the security master now.

Great, thanks a lot!


-- 
To UNSUBSCRIBE, email to debian-bugs-rc-requ...@lists.debian.org
with a subject of unsubscribe. Trouble? Contact listmas...@lists.debian.org



Bug#770425: Fixes for debian stable ?

2014-12-02 Thread Rodrigo Campos
Hi,

The upstream release was on Nov 20, it's been almost 2 weeks and the bug seem
kind of serious. Any chance to do a quick fix and then continue to discuss
changing wordpress version in stable ? Or any ETA on when the fixes will come to
stable ?

I've manually applied the workaround suggested here[1], although it doesn't seem
ideal. But seems to fix the attacks reported here[2] and here[3] at least.






Thanks a lot,
Rodrigo

[1]: http://klikki.fi/adv/wordpress.html
[2]: http://klikki.fi/unquote/
[3]: http://klikki.fi/adv/wordpress_update.html


-- 
To UNSUBSCRIBE, email to debian-bugs-rc-requ...@lists.debian.org
with a subject of unsubscribe. Trouble? Contact listmas...@lists.debian.org



Bug#770425: Fixes for debian stable ?

2014-12-02 Thread Craig Small
On Tue, Dec 02, 2014 at 02:17:37PM +, Rodrigo Campos wrote:
 The upstream release was on Nov 20, it's been almost 2 weeks and the bug seem
 kind of serious. Any chance to do a quick fix and then continue to discuss
 changing wordpress version in stable ? Or any ETA on when the fixes will come 
 to
 stable ?
The stable fix is being uploaded to the security master now.

 - Craig

-- 
Craig Small (@smallsees)   http://enc.com.au/   csmall at : enc.com.au
Debian GNU/Linux   http://www.debian.org/   csmall at : debian.org
GPG fingerprint:5D2F B320 B825 D939 04D2  0519 3938 F96B DF50 FEA5


-- 
To UNSUBSCRIBE, email to debian-bugs-rc-requ...@lists.debian.org
with a subject of unsubscribe. Trouble? Contact listmas...@lists.debian.org