Bug#736804: [src:wordpress] Sourceless flash file

2014-01-27 Thread Ean Schuessler
Those uploader components may be difficult to get around. Drag and drop file uploads can now be done with HTML5 but its fairly recent. If I recall, Flash can also process a directory upload which HTML/Javascript still cannot do. I wonder if upstream would take a patch to remove the Flash dependenc

Bug#736804: [src:wordpress] Sourceless flash file

2014-01-27 Thread Raphael Hertzog
On Mon, 27 Jan 2014, Bastien ROUCARIES wrote: > swf* could be built. DFSG ask you to rebuilt from source. So it is a > policy violation because you do not rebuilt from source DFSG requires to provide the sources, not to rebuild everything. It's a best practice to rebuild from sources but it's not

Bug#736804: [src:wordpress] Sourceless flash file

2014-01-27 Thread Bastien ROUCARIES
On Mon, Jan 27, 2014 at 10:30 AM, Nicolas wrote: > Hi all, > > the problems occured for dotclear package and I removed theses swf files > from doctlear package. And there were exploit with swfupload. There seems to > be fixed with wordpress but I think it's a good idea to remove that stuff. > > As

Bug#736804: [src:wordpress] Sourceless flash file

2014-01-27 Thread Nicolas
Hi all, the problems occured for dotclear package and I removed theses swf files from doctlear package. And there were exploit with swfupload. There seems to be fixed with wordpress but I think it's a good idea to remove that stuff. As far as I understand, I think the real problem with theses swf

Bug#736804: [src:wordpress] Sourceless flash file

2014-01-26 Thread Bastien ROUCARIES
Le 27 janv. 2014 00:26, "Raphael Hertzog" a écrit : > > Hello Bastien, > > On Sun, 26 Jan 2014, bastien ROUCARIES wrote: > > X-Debbugs-CC: ftpmas...@debian.org > > I still don't understand why you CC ftpmasters. Care to explain me? See private mail > > > wordpress 3.8.1+dfsg-1 (source) > > > >

Bug#736804: [src:wordpress] Sourceless flash file

2014-01-26 Thread Raphael Hertzog
Hello Bastien, On Sun, 26 Jan 2014, bastien ROUCARIES wrote: > X-Debbugs-CC: ftpmas...@debian.org I still don't understand why you CC ftpmasters. Care to explain me? > wordpress 3.8.1+dfsg-1 (source) > > wp-includes/js/mediaelement/flashmediaelement.swf This one needs investigation. It co

Bug#736804: [src:wordpress] Sourceless flash file

2014-01-26 Thread bastien ROUCARIES
Package: src:wordpress Version: 3.8.1+dfsg-1 Severity: serious User: debian...@lists.debian.org Usertags: source-contains-prebuilt-flash-object X-Debbugs-CC: ftpmas...@debian.org wordpress 3.8.1+dfsg-1 (source) wp-includes/js/mediaelement/flashmediaelement.swf wp-includes/js/plup