Bug 659319
Summary: | wordpress various flaws [fedora-all] | ||
---|---|---|---|
Product: | [Fedora] Fedora | Reporter: | Jan Lieskovsky <jlieskov> |
Component: | wordpress | Assignee: | Gwyn Ciesla <gwync> |
Status: | CLOSED ERRATA | QA Contact: | Fedora Extras Quality Assurance <extras-qa> |
Severity: | medium | Docs Contact: | |
Priority: | medium | ||
Version: | 14 | CC: | error, gwync, rzhou |
Target Milestone: | --- | Keywords: | Security, SecurityTracking |
Target Release: | --- | ||
Hardware: | All | ||
OS: | Linux | ||
Whiteboard: | |||
Fixed In Version: | Doc Type: | Release Note | |
Doc Text: | Story Points: | --- | |
Clone Of: | Environment: | ||
Last Closed: | 2011-06-01 08:50:17 UTC | Type: | --- |
Regression: | --- | Mount Type: | --- |
Documentation: | --- | CRM: | |
Verified Versions: | Category: | --- | |
oVirt Team: | --- | RHEL 7.3 requirements from Atomic Host: | |
Cloudforms Team: | --- | Target Upstream Version: | |
Embargoed: | |||
Bug Depends On: | |||
Bug Blocks: | 659265, 659294, 659299, 662139 |
Description
Jan Lieskovsky
2010-12-02 14:44:30 UTC
Adding parent bug 659294 New bodhi update url: https://admin.fedoraproject.org/updates/new/?type_=security&bugs=659265,659294 Adding parent bug 659299 New bodhi update url: https://admin.fedoraproject.org/updates/new/?type_=security&bugs=659265,659294,659299 I'm unclear after reading the above, does this affect just 3.0.1, or the 2.8.x series as well? Updated in rawhide, which is currently the only branch with 3.0.x. Adding parent bug 662139 New bodhi update url: https://admin.fedoraproject.org/updates/new/?type_=security&bugs=659265,659294,659299,662139 3.0.3 is now in rawhide. Jon, it affects 2.x too, ricky tested it with our blogs.fedoraproject.org wordpress-mu *** Bug 664886 has been marked as a duplicate of this bug. *** Affects 2.x and 3.x. Unfortunately (or perhaps fortunately, depending on your perspective) WordPress rarely opens tickets in their bug tracker for security issues; they prefer to handle those on a private mailing list, as their tracker doesn't provide a way to restrict access to security sensitive bugs. This looks like a ridiculously simple backport, though: http://core.trac.wordpress.org/changeset/16625 wordpress-mu-2.9.2-2.fc13 has been submitted as an update for Fedora 13. https://admin.fedoraproject.org/updates/wordpress-mu-2.9.2-2.fc13 wordpress-mu-2.9.2-2.fc14 has been submitted as an update for Fedora 14. https://admin.fedoraproject.org/updates/wordpress-mu-2.9.2-2.fc14 wordpress-mu-2.9.2-2.el5 has been submitted as an update for Fedora EPEL 5. https://admin.fedoraproject.org/updates/wordpress-mu-2.9.2-2.el5 |