Path to this page:
./
www/wordpress,
Blogging tool written in php
Branch: pkgsrc-2012Q4,
Version: 3.5.1,
Package name: wordpress-3.5.1,
Maintainer: morrWordPress is a state-of-the-art publishing platform with a focus on
aesthetics, web standards, and usability. WordPress is both free and
priceless at the same time.
Required to run:[
databases/php-mysql] [
www/ap-php]
Required to build:[
lang/perl5] [
www/apache22]
Package options: ap-php
Master sites:
SHA1: 3c1b6e4da8132aa31408bbd2d4e86062a99b77ef
RMD160: baf0460f7be83f8fc952e4b299010679e17bfd49
Filesize: 4895.236 KB
Version history: (Expand)
- (2013-01-27) Updated to version: wordpress-3.5.1
- (2013-01-06) Package added to pkgsrc.se, version wordpress-3.5 (created)
CVS history: (Expand)
2013-01-27 15:06:48 by S.P.Zeidler | Files touched by this commit (3) | |
Log message:
Pullup ticket #4042 - requested by morr
www/wordpress: security update
Revisions pulled up:
- www/wordpress/Makefile 1.30
- www/wordpress/PLIST 1.14
- www/wordpress/distinfo 1.24
-------------------------------------------------------------------
Module Name: pkgsrc
Committed By: morr
Date: Sun Jan 27 07:51:37 UTC 2013
Modified Files:
pkgsrc/www/wordpress: Makefile PLIST distinfo
Log message:
This maintenance release addresses 37 bugs with version 3.5, including:
* Editor: Prevent certain HTML elements from being unexpectedly removed or
modified in rare cases.
* Media: Fix a collection of minor workflow and compatibility issues in the new
media manager.
* Networks: Suggest proper rewrite rules when creating a new network.
* Prevent scheduled posts from being stripped of certain HTML, such as video
embeds, when they are published.
* Work around some misconfigurations that may have caused some JavaScript in
the WordPress admin area to fail.
* Suppress some warnings that could occur when a plugin misused the database or
user APIs.
Additionally: Version 3.5.1 fixes a few security issues:
* Server-side request forgery (SSRF) and remote port scanning via pingbacks.
Fixed by the WordPress security team.
* Cross-site scripting (XSS) via shortcodes and post content. Discovered by Jon
Cave of the WordPress security team.
* Cross-site scripting (XSS) in the external library Plupload. Plupload 1.5.5
was released to address this issue.
To generate a diff of this commit:
cvs rdiff -u -r1.29 -r1.30 pkgsrc/www/wordpress/Makefile
cvs rdiff -u -r1.13 -r1.14 pkgsrc/www/wordpress/PLIST
cvs rdiff -u -r1.23 -r1.24 pkgsrc/www/wordpress/distinfo
|