pkgsrc-Changes archive

[Date Prev][Date Next][Thread Prev][Thread Next][Date Index][Thread Index][Old Index]

CVS commit: [pkgsrc-2013Q2] pkgsrc/www/wordpress

Module Name:    pkgsrc
Committed By:   tron
Date:           Fri Sep 13 13:07:27 UTC 2013

Modified Files:
        pkgsrc/www/wordpress [pkgsrc-2013Q2]: Makefile PLIST distinfo

Log Message:
Pullup ticket #4234 - requested by morr
www/wordpress: security update

Revisions pulled up:
- www/wordpress/Makefile                                        1.34-1.35
- www/wordpress/PLIST                                           1.16-1.17
- www/wordpress/distinfo                                        1.26-1.27

   Module Name:    pkgsrc
   Committed By:   morr
   Date:           Thu Aug  8 07:50:58 UTC 2013

   Modified Files:
           pkgsrc/www/wordpress: Makefile PLIST distinfo

   Log Message:
   Update to newest version of Wordpress 3.6.


   New Default Theme - Twenty Thirteen
   * Focus on blogging
   * Single column layout with Sidebar / Widgets in the footer
   * Latest Theme Features support, particularly Post Formats and Semantic 
   * Font-based icons (Genericons)

   Admin Enhancements
   * UI improvements on Navigation Menus Screen
   * Revisions revised to be more dynamic and scalable
   * Autosave and Post Locking
   * Preview Audio and Video on Media Edit Screen
   * In-line login following expired sessions

   For Developers
   * External Libraries have been updated.
   * New audio/video APIs give developers access to powerful media metadata, 
   ID3 tags.
   * Filters for revisions, allowing you to set the number of revisions ad hoc
   instead of only via a define.
   * Semantic Markup allows themes to choose improved HTML5 markup for search
   forms, comment forms, and comment lists.
   * Search content for shortcodes with has_shortcode() and adjust shortcode
   attributes with a new filter.

   More info on

   Module Name:    pkgsrc
   Committed By:   morr
   Date:           Thu Sep 12 17:19:59 UTC 2013

   Modified Files:
           pkgsrc/www/wordpress: Makefile PLIST distinfo

   Log Message:
   This maintenance release addresses 13 bugs with version 3.6.

   Additionally: Version 3.6.1 fixes three security issues:

   * Remote Code Execution: Block unsafe PHP de-serialization that could occur 
   limited situations and setups, which can lead to remote code execution.
   Reported by Tom Van Goethem. CVE-2013-4338.
   * Link Injection / Open Redirect: Fix insufficient input validation that 
   result in redirecting or leading a user to another website.
   Reported by Dave Cummo, a Northrup Grumman subcontractor for the U.S. Centers
   for Disease Control and Prevention. CVE-2013-4339.
   * Privilege Escalation: Prevent a user with an Author role, using a specially
   crafted request, from being able to create a post "written by" another user.
   Reported by Anakorn Kyavatanakij. CVE-2013-4340.

   Additional security hardening:

   * Updated security restrictions around file uploads to mitigate the potential
   for cross-site scripting. The extensions .swf and .exe are no longer allowed
   by default, and .htm and .html are only allowed if the user has the ability
   to use unfiltered HTML.

   More on

To generate a diff of this commit:
cvs rdiff -u -r1.33 -r1.33.2.1 pkgsrc/www/wordpress/Makefile
cvs rdiff -u -r1.15 -r1.15.2.1 pkgsrc/www/wordpress/PLIST
cvs rdiff -u -r1.25 -r1.25.2.1 pkgsrc/www/wordpress/distinfo

Please note that diffs are not public domain; they are subject to the
copyright notices on the relevant files.

Home | Main Index | Thread Index | Old Index