Re: Security update of Wordpress

2016-08-17 Thread Craig Small
It's probably best to compare the 4.1.12 upstream version and make sure it follows whatever they do there. That in theory has been tested. I'm surprised there was a database update skipped. And yes the security bug was around having comments too long. I forget the exact attack method but it was o

Re: Security update of Wordpress

2016-08-20 Thread Craig Small
The problem with a blank screen means basically something went wrong, with that level of usefullness. So it could be the exact same problem OR it could be something completely different. Just to be clear, you installed 3.6.1+dfsg-1~deb7u1 from a clean system and had problems? - Craig

Re: Security update of Wordpress

2016-08-20 Thread Craig Small
Hi Brian, Ok thats something reasonably easy to reproduce unlike the zillion different upgrade paths which are tricky. Ill load one up and see what I get. - Craig On Sun, 21 Aug 2016, 12:56 PM Brian May wrote: > Craig Small writes: > > > Just to be clear, you installed 3.6.1+d

Re: Wordpress security update

2016-09-17 Thread Craig Small
Hi Markus, I certainly did find them useful as 4029, 6634 and 6635 was on my next TODO list and you've done them for me! Good catch on the JsonSerialisable interface, I was wondering how you noticed it was missing? Just good eye or ran it through something? - Craig On Sat, Sep 17, 2016 at 8:3

Re: Wordpress security update

2017-03-14 Thread Craig Small
/branches/4.1 3: https://core.trac.wordpress.org/changeset/40176/branches/4.1 > -- Craig Small (@smallsees) http://dropbear.xyz/ csmall at : enc.com.au Debian GNU/Linux http://www.debian.org/ csmall at : debian.org GPG fingerprint:5D2F B320 B825 D939 04D2 0519 3938 F96B D

Re: Wordpress security update

2017-03-15 Thread Craig Small
to add those to the security package too. - Craig -- Craig Small (@smallsees) http://dropbear.xyz/ csmall at : enc.com.au Debian GNU/Linux http://www.debian.org/ csmall at : debian.org GPG fingerprint:5D2F B320 B825 D939 04D2 0519 3938 F96B DF50 FEA5

Re: Wordpress security update

2017-03-15 Thread Craig Small
Great stuff, I have rebuilt them with the two missing functions, just need the ok to upload. - Craig On Wed, Mar 15, 2017 at 10:01 PM Sébastien Delafond wrote: > On Mar/15, Craig Small wrote: > > Damn, you're right. I missed that. Upstream missed it too! I'll need >

Re: Wordpress security update

2017-03-15 Thread Craig Small
I saw the rejection of the old package so uploaded it and the new second package got rejected so something is unhappy about all of this. - Craig On Thu, Mar 16, 2017 at 6:23 AM Craig Small wrote: > Great stuff, > I have rebuilt them with the two missing functions, just need the

Re: #862816 and CVE-2017-9066

2017-06-06 Thread Craig Small
rks on wordpress 4.1, I'd be glad to see it! - Craig > > -- Craig Small https://dropbear.xyz/ csmall at : enc.com.au Debian GNU/Linuxhttps://www.debian.org/ csmall at : debian.org Mastodon: @smalls...@social.dropbear.xyz Twitter: @smallsees GPG fing

Re: Confusing our users - who is supporting LTS?

2018-10-22 Thread Craig Small
ine, but stating that anywhere muddies the waters. Not an ideal situation and you'll still cop some emails but it might help. - Craig > -- Craig Small https://dropbear.xyz/ csmall at : dropbear.xyz Debian GNU/Linuxhttps://www.debian.org/ csmall at : debian.org Ma

Wordpress fix

2014-08-08 Thread Craig Small
Hi, Wordpress has had some security updates on 3.9.2 I have backported these changesets to the wheezy and now to squeeze. Attached is the debdiff for review. - Craig -- Craig Small (@smallsees) http://enc.com.au/ csmall at : enc.com.au Debian GNU/Linux http://www.debian.org

Re: squeeze update of wordpress?

2015-08-14 Thread Craig Small
tter to try to fix all of the outstanding CVEs? > Would you like to take care of this yourself? We are still understaffed so > any help is always highly appreciated. I'll give it a go I got to fix jessie with CVE-2015-5730 first. - Craig -- Craig Small (@smallsees) http://en

Re: squeeze update of wordpress?

2015-08-14 Thread Craig Small
t, testing it will be tricky. - Craig -- Craig Small (@smallsees) http://enc.com.au/ csmall at : enc.com.au Debian GNU/Linux http://www.debian.org/ csmall at : debian.org GPG fingerprint:5D2F B320 B825 D939 04D2 0519 3938 F96B DF50 FEA5

Re: squeeze update of wordpress?

2015-08-14 Thread Craig Small
ixes into squeeze. As they use the same base version the packages should work fine and its just a matter of copying them across. I got it completed in git, but not sure what happens next. - Craig -- Craig Small (@smallsees) http://enc.com.au/ csmall at : enc.com.au Debian

Re: squeeze update of wordpress?

2015-08-15 Thread Craig Small
Awesome. So you're happy to build of the git branch then? -- Craig Small (@smallsees) http://enc.com.au/ csmall at : enc.com.au Debian GNU/Linux http://www.debian.org/ csmall at : debian.org GPG fingerprint:5D2F B320 B825 D939 04D2 0519 3938 F96B DF50 FEA5

Re: Security update of Wordpress

2016-07-31 Thread Craig Small
I had a similar query from the security team. I think you are looking for changeset 37798. I got a security update but waiting on the team. I cannot see why 4.1.12 doesn't have this. https://core.trac.wordpress.org/changeset/37798 - Craig On Tue, Jul 26, 2016 at 4:42 PM Markus Koschany wrote