Bug#713947: wordpress: Multiple security issues

2013-06-27 Thread Raphael Hertzog
Hi, On Tue, 25 Jun 2013, Moritz Muehlenhoff wrote: > On Tue, Jun 25, 2013 at 04:06:58PM +0200, Raphael Hertzog wrote: > > An upload to unstable will quickly follow. Can I upload 3.5.2+dfsg-1 as > > 3.5.2+dfsg-1~wheezy1 to wheezy-security ? > > I won't be able to handle the DSA; but yes, please go

Bug#713947: wordpress: Multiple security issues

2013-06-25 Thread Yves-Alexis Perez
On mer., 2013-06-26 at 00:41 +0200, Raphael Hertzog wrote: > On Tue, 25 Jun 2013, Yves-Alexis Perez wrote: > > On mar., 2013-06-25 at 23:22 +0200, Moritz Mühlenhoff wrote: > > > > As we already pushed new upstream releases to > > > > Squeeze, it might make sense to keep going that way (I have a bit

Bug#713947: wordpress: Multiple security issues

2013-06-25 Thread Raphael Hertzog
On Tue, 25 Jun 2013, Yves-Alexis Perez wrote: > On mar., 2013-06-25 at 23:22 +0200, Moritz Mühlenhoff wrote: > > > As we already pushed new upstream releases to > > > Squeeze, it might make sense to keep going that way (I have a bit of > > > fear that every webapp ends up like that but eh). > > >

Bug#713947: wordpress: Multiple security issues

2013-06-25 Thread Yves-Alexis Perez
On mar., 2013-06-25 at 23:22 +0200, Moritz Mühlenhoff wrote: > > As we already pushed new upstream releases to > > Squeeze, it might make sense to keep going that way (I have a bit of > > fear that every webapp ends up like that but eh). > > I suppose the leap between 3.3 and 3.5 would be too high

Bug#713947: wordpress: Multiple security issues

2013-06-25 Thread Moritz Mühlenhoff
On Tue, Jun 25, 2013 at 10:52:24PM +0200, Yves-Alexis Perez wrote: > On mar., 2013-06-25 at 18:34 +0200, Moritz Muehlenhoff wrote: > > For lenny we should announce it's end of life as we recently did in the > > chromium and icewerasel DSAs. Agreed? > > I think you mean Squeeze? Yes. > As we alr

Bug#713947: wordpress: Multiple security issues

2013-06-25 Thread Yves-Alexis Perez
On mar., 2013-06-25 at 18:34 +0200, Moritz Muehlenhoff wrote: > For lenny we should announce it's end of life as we recently did in the > chromium and icewerasel DSAs. Agreed? I think you mean Squeeze? As we already pushed new upstream releases to Squeeze, it might make sense to keep going that wa

Bug#713947: wordpress: Multiple security issues

2013-06-25 Thread Julien Cristau
On Tue, Jun 25, 2013 at 18:34:53 +0200, Moritz Muehlenhoff wrote: > On Tue, Jun 25, 2013 at 04:06:58PM +0200, Raphael Hertzog wrote: > > On Mon, 24 Jun 2013, Moritz Muehlenhoff wrote: > > > Wordpress 3.5.2 fixes multiple security issues. Quoting from > > > http://codex.wordpress.org/Version_3.5.2

Bug#713947: wordpress: Multiple security issues

2013-06-25 Thread Moritz Muehlenhoff
On Tue, Jun 25, 2013 at 04:06:58PM +0200, Raphael Hertzog wrote: > On Mon, 24 Jun 2013, Moritz Muehlenhoff wrote: > > Wordpress 3.5.2 fixes multiple security issues. Quoting from > > http://codex.wordpress.org/Version_3.5.2: > > An upload to unstable will quickly follow. Can I upload 3.5.2+dfsg-1

Bug#713947: wordpress: Multiple security issues

2013-06-23 Thread Moritz Muehlenhoff
Package: wordpress Severity: grave Tags: security Justification: user security hole Wordpress 3.5.2 fixes multiple security issues. Quoting from http://codex.wordpress.org/Version_3.5.2: Additionally: Version 3.5.2 fixes seven security issues: * Server-Side Request Forgery (SSRF) via the HTTP A