Bug#497216: wordpress: CVE-2008-3747 information leak, does not always force ssl

2008-08-31 Thread Andrea De Iacovo
Hi, the following CVE (Common Vulnerabilities Exposures) id was published for wordpress. Hello and thank you for reporting. There is a patch on: http://trac.wordpress.org/attachment/ticket/7359/edit_links_ssl.diff The patch appears to be good. I should be able to provide the new package

Bug#497216: wordpress: CVE-2008-3747 information leak, does not always force ssl

2008-08-31 Thread Andrea De Iacovo
Hi I've made a new wordpress package [1] to fix cve-2008-3747. Could you please upload it? [1]: http://mentors.debian.net/debian/pool/main/w/wordpress Thank you very much. Cheers Andrea De Iacovo signature.asc Description: Questa รจ una parte del messaggio firmata digitalmente

Bug#497216: wordpress: CVE-2008-3747 information leak, does not always force ssl

2008-08-31 Thread Thijs Kinkhorst
I've made a new wordpress package [1] to fix cve-2008-3747. Could you please upload it? uploaded, thanks! Thijs pgpREQrMbjpUM.pgp Description: PGP signature

Bug#497216: wordpress: CVE-2008-3747 information leak, does not always force ssl

2008-08-30 Thread Nico Golde
Package: wordpress Severity: grave Tags: security patch Hi, the following CVE (Common Vulnerabilities Exposures) id was published for wordpress. CVE-2008-3747[0]: | The (1) get_edit_post_link and (2) get_edit_comment_link functions in | wp-includes/link-template.php in WordPress before 2.6.1 do