Re: squeeze update of wordpress?

2015-08-15 Thread Craig Small
Awesome. So you're happy to build of the git branch then? -- Craig Small (@smallsees) http://enc.com.au/ csmall at : enc.com.au Debian GNU/Linux http://www.debian.org/ csmall at : debian.org GPG fingerprint:5D2F B320 B825 D939 04D2 0519 3938 F96B DF50 FEA5

Accepted wordpress 3.6.1+dfsg-1~deb6u7 (source all) into squeeze-lts

2015-08-19 Thread Craig Small
Changed-By: Craig Small csm...@debian.org Description: wordpress - weblog manager wordpress-l10n - weblog manager - language files Changes: wordpress (3.6.1+dfsg-1~deb6u7) squeeze-lts; urgency=medium . * Non-maintainer upload. * Backports of security patches from Wheezy deb7u7 - CVE

Re: squeeze update of wordpress?

2015-08-14 Thread Craig Small
to keep it like that. Do you have plans for Wheezy yet? Wheezy has pending patches for 3.6.1 waiting for security OK. My plan was to just copy those patches down to squeeze as its the same base wordpress they should be ok. Other than running php lint, testing it will be tricky. - Craig -- Craig

Re: squeeze update of wordpress?

2015-08-14 Thread Craig Small
into squeeze. As they use the same base version the packages should work fine and its just a matter of copying them across. I got it completed in git, but not sure what happens next. - Craig -- Craig Small (@smallsees) http://enc.com.au/ csmall at : enc.com.au Debian GNU/Linux http

Re: Security update of Wordpress

2016-08-17 Thread Craig Small
It's probably best to compare the 4.1.12 upstream version and make sure it follows whatever they do there. That in theory has been tested. I'm surprised there was a database update skipped. And yes the security bug was around having comments too long. I forget the exact attack method but it was

Re: Security update of Wordpress

2016-08-20 Thread Craig Small
The problem with a blank screen means basically something went wrong, with that level of usefullness. So it could be the exact same problem OR it could be something completely different. Just to be clear, you installed 3.6.1+dfsg-1~deb7u1 from a clean system and had problems? - Craig

Re: Security update of Wordpress

2016-08-20 Thread Craig Small
Hi Brian, Ok thats something reasonably easy to reproduce unlike the zillion different upgrade paths which are tricky. Ill load one up and see what I get. - Craig On Sun, 21 Aug 2016, 12:56 PM Brian May <b...@debian.org> wrote: > Craig Small <csm...@debian.org> writes: > &g

Re: Wordpress security update

2017-03-15 Thread Craig Small
too! I'll need to add those to the security package too. - Craig -- Craig Small (@smallsees) http://dropbear.xyz/ csmall at : enc.com.au Debian GNU/Linux http://www.debian.org/ csmall at : debian.org GPG fingerprint:5D2F B320 B825 D939 04D2 0519 3938 F96B DF50 FEA5

Re: Wordpress security update

2017-03-14 Thread Craig Small
/branches/4.1 3: https://core.trac.wordpress.org/changeset/40176/branches/4.1 > -- Craig Small (@smallsees) http://dropbear.xyz/ csmall at : enc.com.au Debian GNU/Linux http://www.debian.org/ csmall at : debian.org GPG fingerprint:5D2F B320 B825 D939 04D2 0519 3938 F96B D

Re: #862816 and CVE-2017-9066

2017-06-06 Thread Craig Small
patch that works on wordpress 4.1, I'd be glad to see it! - Craig > > -- Craig Small https://dropbear.xyz/ csmall at : enc.com.au Debian GNU/Linuxhttps://www.debian.org/ csmall at : debian.org Mastodon: @smalls...@social.dropbear.xyz Twitter: @smallsees G