Package: wordpress
Version: 2.0.9-1
Severity: grave
Tags: security
Justification: user security hole


The upstream 2.0.10 release notes claim that it fixes security problems,
especially with the XML-RPC module. The diff applies cleanly to the packaged
files, and appears to run fine on my machine. Suggest update.

The diff:

svn diff http://svn.automattic.com/wordpress/tags/2.0.9/ 
http://svn.automattic.com/wordpress/tags/2.0.10/

-- System Information:
Debian Release: 4.0
  APT prefers stable
  APT policy: (500, 'stable')
Architecture: i386 (i686)
Shell:  /bin/sh linked to /bin/bash
Kernel: Linux 2.4.27-2-386
Locale: LANG=en_US.UTF-8, LC_CTYPE=en_US.UTF-8 (charmap=UTF-8)

Versions of packages wordpress depends on:
ii  apache2-mpm-prefork [htt 2.2.3-4         Traditional model for Apache HTTPD
ii  libapache2-mod-php4      6:4.4.4-8+etch2 server-side, HTML-embedded scripti
ii  mysql-client-5.0 [virtua 5.0.32-7etch1   mysql database client binaries
ii  php4-mysql               6:4.4.4-8+etch2 MySQL module for php4

wordpress recommends no packages.

-- no debconf information


-- 
To UNSUBSCRIBE, email to [EMAIL PROTECTED]
with a subject of "unsubscribe". Trouble? Contact [EMAIL PROTECTED]

Reply via email to