Bug#784603: wordpress: Wordpress 4.2.2 critical security release

2015-05-28 Thread Craig Small
On Tue, May 26, 2015 at 06:43:15PM +0100, Rodrigo Campos wrote: > Sorry to bother again, Craig. But any news on this? Bug opened #786886 which we will see if 4.1.5 gets in. - Craig -- Craig Small (@smallsees) http://enc.com.au/ csmall at : enc.com.au Debian GNU/Linux http://ww

Bug#784603: wordpress: Wordpress 4.2.2 critical security release

2015-05-26 Thread Rodrigo Campos
On Wed, May 20, 2015 at 10:08:44PM +1000, Craig Small wrote: > On Mon, May 18, 2015 at 10:12:21AM +0200, Raphael Hertzog wrote: > > That's the general case. But with wordpress, the security team is rather > > open to integrate new upstream releases. We did it multiple times already. > > Let me ask

Bug#784603: wordpress: Wordpress 4.2.2 critical security release

2015-05-20 Thread Craig Small
On Mon, May 18, 2015 at 10:12:21AM +0200, Raphael Hertzog wrote: > That's the general case. But with wordpress, the security team is rather > open to integrate new upstream releases. We did it multiple times already. Let me ask them. I'd prefer to just use 4.1.5 in that case. - Craig -- Craig S

Bug#784603: wordpress: Wordpress 4.2.2 critical security release

2015-05-18 Thread Rodrigo Campos
On Mon, May 18, 2015 at 10:12:21AM +0200, Raphael Hertzog wrote: > On Sat, 16 May 2015, Craig Small wrote: > > > I mean, instead of using 4.2.x to extract the patches and backport, isn't > > > it > > > easier to extract them from 4.1.x for stable ? Or just do a "new upstream > > > release" based o

Bug#784603: wordpress: Wordpress 4.2.2 critical security release

2015-05-18 Thread Raphael Hertzog
On Sat, 16 May 2015, Craig Small wrote: > > I mean, instead of using 4.2.x to extract the patches and backport, isn't it > > easier to extract them from 4.1.x for stable ? Or just do a "new upstream > > release" based on 4.1.5 ? > The stable track is basically whatever version was there with securi

Bug#784603: wordpress: Wordpress 4.2.2 critical security release

2015-05-15 Thread Craig Small
On Fri, May 15, 2015 at 03:09:35PM +0100, Rodrigo Campos wrote: > doing things quite different. And doing this "code reorganization" would have > fixed the XSS bug fixed in 4.2.1, but requires more time and test, so 4.2.1 > was > released and then 4.2.2 improved things. But, no idea, just thinking

Bug#784603: wordpress: Wordpress 4.2.2 critical security release

2015-05-15 Thread Rodrigo Campos
On Fri, May 15, 2015 at 02:35:45PM +0100, Rodrigo Campos wrote: > On Fri, May 15, 2015 at 09:08:28PM +1000, Craig Small wrote: > > On Thu, May 07, 2015 at 05:31:03AM +0100, Rodrigo Campos wrote: > > > A new Wordpress *critical* security release has been announced here: > > > https://wordpress.org/n

Bug#784603: wordpress: Wordpress 4.2.2 critical security release

2015-05-15 Thread Rodrigo Campos
On Fri, May 15, 2015 at 09:08:28PM +1000, Craig Small wrote: > On Thu, May 07, 2015 at 05:31:03AM +0100, Rodrigo Campos wrote: > > A new Wordpress *critical* security release has been announced here: > > https://wordpress.org/news/2015/05/wordpress-4-2-2/ > > > > Can you please update and backport

Bug#784603: wordpress: Wordpress 4.2.2 critical security release

2015-05-15 Thread Craig Small
On Thu, May 07, 2015 at 05:31:03AM +0100, Rodrigo Campos wrote: > A new Wordpress *critical* security release has been announced here: > https://wordpress.org/news/2015/05/wordpress-4-2-2/ > > Can you please update and backport the patches to stable ? > Also, let me know if you need help to backpo

Bug#784603: wordpress: Wordpress 4.2.2 critical security release

2015-05-06 Thread Rodrigo Campos
Source: wordpress Version: 4.1+dfsg-1+deb8u1 Severity: important Dear Maintainer, A new Wordpress *critical* security release has been announced here: https://wordpress.org/news/2015/05/wordpress-4-2-2/ Can you please update and backport the patches to stable ? Also, let me know if you need hel