Bug#987065: wordpress: CVE-2021-29450: Authenticated disclosure of password-protected posts and pages

2021-04-17 Thread Salvatore Bonaccorso
Hi, On Sat, Apr 17, 2021 at 09:22:09PM +1000, Craig Small wrote: > Yeah I realised there wasn't PHP 8 in Debian anywhere yet but referencing > it is worthwhile otherwise months later someone might ask me about it and > I'll go, hmm I think we fixed that. Ack. > Buster will have a debdiff to revi

Bug#987065: wordpress: CVE-2021-29450: Authenticated disclosure of password-protected posts and pages

2021-04-17 Thread Craig Small
Yeah I realised there wasn't PHP 8 in Debian anywhere yet but referencing it is worthwhile otherwise months later someone might ask me about it and I'll go, hmm I think we fixed that. Buster will have a debdiff to review very soon. Bullseye I have asked for the version in Sid to be unblocked in #9

Bug#987065: wordpress: CVE-2021-29450: Authenticated disclosure of password-protected posts and pages

2021-04-16 Thread Salvatore Bonaccorso
Hi Craig, On Sat, Apr 17, 2021 at 08:32:35AM +1000, Craig Small wrote: > Should CVE-2021-29447 [1] be also listed against this bug? I'll be putting > it in the changelog. I choosed to explicitly cover only CVE-2021-29450 with this bug because CVE-2021-29447 while fixed as well with 5.7.1, is only

Bug#987065: wordpress: CVE-2021-29450: Authenticated disclosure of password-protected posts and pages

2021-04-16 Thread Craig Small
Should CVE-2021-29447 [1] be also listed against this bug? I'll be putting it in the changelog. How good is it when WordPress raise their own CVEs! One glorious day they will put them in their announcements too. 1: https://github.com/WordPress/wordpress-develop/security/advisories/GHSA-rv47-pc52-

Bug#987065: wordpress: CVE-2021-29450: Authenticated disclosure of password-protected posts and pages

2021-04-16 Thread Salvatore Bonaccorso
Source: wordpress Version: 5.7+dfsg1-1 Severity: grave Tags: security upstream Justification: user security hole X-Debbugs-Cc: car...@debian.org, Debian Security Team Control: found -1 5.0.11+dfsg1-0+deb10u1 Hi, The following vulnerability was published for wordpress. CVE-2021-29450[0]: | Wordp