Bug#713947: wordpress: Multiple security issues

2013-06-27 Thread Raphael Hertzog
Hi, On Tue, 25 Jun 2013, Moritz Muehlenhoff wrote: On Tue, Jun 25, 2013 at 04:06:58PM +0200, Raphael Hertzog wrote: An upload to unstable will quickly follow. Can I upload 3.5.2+dfsg-1 as 3.5.2+dfsg-1~wheezy1 to wheezy-security ? I won't be able to handle the DSA; but yes, please go ahead

Bug#713947: wordpress: Multiple security issues

2013-06-25 Thread Moritz Muehlenhoff
On Tue, Jun 25, 2013 at 04:06:58PM +0200, Raphael Hertzog wrote: On Mon, 24 Jun 2013, Moritz Muehlenhoff wrote: Wordpress 3.5.2 fixes multiple security issues. Quoting from http://codex.wordpress.org/Version_3.5.2: An upload to unstable will quickly follow. Can I upload 3.5.2+dfsg-1 as

Bug#713947: wordpress: Multiple security issues

2013-06-25 Thread Julien Cristau
On Tue, Jun 25, 2013 at 18:34:53 +0200, Moritz Muehlenhoff wrote: On Tue, Jun 25, 2013 at 04:06:58PM +0200, Raphael Hertzog wrote: On Mon, 24 Jun 2013, Moritz Muehlenhoff wrote: Wordpress 3.5.2 fixes multiple security issues. Quoting from http://codex.wordpress.org/Version_3.5.2:

Bug#713947: wordpress: Multiple security issues

2013-06-25 Thread Yves-Alexis Perez
On mar., 2013-06-25 at 18:34 +0200, Moritz Muehlenhoff wrote: For lenny we should announce it's end of life as we recently did in the chromium and icewerasel DSAs. Agreed? I think you mean Squeeze? As we already pushed new upstream releases to Squeeze, it might make sense to keep going that way

Bug#713947: wordpress: Multiple security issues

2013-06-25 Thread Moritz Mühlenhoff
On Tue, Jun 25, 2013 at 10:52:24PM +0200, Yves-Alexis Perez wrote: On mar., 2013-06-25 at 18:34 +0200, Moritz Muehlenhoff wrote: For lenny we should announce it's end of life as we recently did in the chromium and icewerasel DSAs. Agreed? I think you mean Squeeze? Yes. As we already

Bug#713947: wordpress: Multiple security issues

2013-06-25 Thread Yves-Alexis Perez
On mar., 2013-06-25 at 23:22 +0200, Moritz Mühlenhoff wrote: As we already pushed new upstream releases to Squeeze, it might make sense to keep going that way (I have a bit of fear that every webapp ends up like that but eh). I suppose the leap between 3.3 and 3.5 would be too high, but I

Bug#713947: wordpress: Multiple security issues

2013-06-25 Thread Raphael Hertzog
On Tue, 25 Jun 2013, Yves-Alexis Perez wrote: On mar., 2013-06-25 at 23:22 +0200, Moritz Mühlenhoff wrote: As we already pushed new upstream releases to Squeeze, it might make sense to keep going that way (I have a bit of fear that every webapp ends up like that but eh). I suppose

Bug#713947: wordpress: Multiple security issues

2013-06-25 Thread Yves-Alexis Perez
On mer., 2013-06-26 at 00:41 +0200, Raphael Hertzog wrote: On Tue, 25 Jun 2013, Yves-Alexis Perez wrote: On mar., 2013-06-25 at 23:22 +0200, Moritz Mühlenhoff wrote: As we already pushed new upstream releases to Squeeze, it might make sense to keep going that way (I have a bit of

Bug#713947: wordpress: Multiple security issues

2013-06-24 Thread Moritz Muehlenhoff
Package: wordpress Severity: grave Tags: security Justification: user security hole Wordpress 3.5.2 fixes multiple security issues. Quoting from http://codex.wordpress.org/Version_3.5.2: Additionally: Version 3.5.2 fixes seven security issues: * Server-Side Request Forgery (SSRF) via the HTTP