Your message dated Wed, 2 Sep 2020 13:05:10 +1000
with message-id 
<caly8cw5jhgdtb04nanksrpv8haue8awnwxpemg+t1ztwb3e...@mail.gmail.com>
and subject line Security releases use upstream version
has caused the Debian Bug report #642301,
regarding wordpress: Please include the debian sub-version in the header
to be marked as done.

This means that you claim that the problem has been dealt with.
If this is not the case it is now your responsibility to reopen the
Bug report if necessary, and/or fix the problem forthwith.

(NB: If you are a system administrator and have no idea what this
message is talking about, this may indicate a serious mail system
misconfiguration somewhere. Please contact [email protected]
immediately.)


-- 
642301: https://bugs.debian.org/cgi-bin/bugreport.cgi?bug=642301
Debian Bug Tracking System
Contact [email protected] with problems
--- Begin Message ---
Package: wordpress
Version: 3.0.5+dfsg-0+squeeze1
Severity: wishlist

Google sends out alerts warning site owners if their version of wordpress is 
out of date, because of the risk of security issues.

However debian already handles the security issues even on old versions, so 
there is no reason for google to alert such users.

But, there is no way for google to tell since the header doesn't say:

    <meta name="generator" content="WordPress 3.0.5" />

So, please include the full debian sub-version in the header (or in an 
additional one), that way google can do a better job with alerts, including 
alerting if someone has an unapplied debian update.

-- System Information:
Debian Release: 6.0.2
  APT prefers stable
  APT policy: (990, 'stable'), (500, 'oldstable'), (1, 'experimental')
Architecture: i386 (x86_64)

Kernel: Linux 2.6.32 (SMP w/8 CPU cores)
Locale: LANG=C, LC_CTYPE=C (charmap=ANSI_X3.4-1968)
Shell: /bin/sh linked to /bin/bash

Versions of packages wordpress depends on:
ii  apache2                2.2.16-6+squeeze3 Apache HTTP Server metapackage
ii  apache2-mpm-prefork [h 2.2.16-6+squeeze3 Apache HTTP Server - traditional n
ii  libapache2-mod-php5    5.3.3-7+squeeze3  server-side, HTML-embedded scripti
pn  libjs-cropper          <none>            (no description available)
pn  libjs-jquery           <none>            (no description available)
ii  libjs-prototype        1.6.1-1           JavaScript Framework for dynamic w
pn  libjs-scriptaculous    <none>            (no description available)
pn  libphp-phpmailer       <none>            (no description available)
pn  libphp-snoopy          <none>            (no description available)
ii  mysql-client           5.1.49-3          MySQL database client (metapackage
ii  mysql-client-5.1 [mysq 5.1.49-3          MySQL database client binaries
pn  php-gettext            <none>            (no description available)
ii  php5                   5.3.3-7+squeeze3  server-side, HTML-embedded scripti
ii  php5-gd                5.3.3-7+squeeze3  GD module for php5
ii  php5-mysql             5.3.3-7+squeeze3  MySQL module for php5
pn  tinymce                <none>            (no description available)

Versions of packages wordpress recommends:
pn  wordpress-l10n                <none>     (no description available)

Versions of packages wordpress suggests:
ii  mysql-server                  5.1.49-3   MySQL database server (metapackage
ii  mysql-server-5.1 [mysql-serve 5.1.49-3   MySQL database server binaries and



--- End Message ---
--- Begin Message ---
The new way of updating the security releases of WordPress is to use
the upstream's version number. A good example of this is buster that
uses 5.0.10

So any intelligent scanning system should realise these systems are
patched correctly.

 - Craig

--- End Message ---

Reply via email to