Subject: CVS commit: [pkgsrc-2009Q3] pkgsrc/www/wordpress
From: Matthias Scheler
Date: 2009-11-13 12:07:27
Message id: 20091113110727.D0616175DD@cvs.netbsd.org

Log Message:
Pullup ticket #2933 - requested by adrianp
wordpress: security update

Revisions pulled up:
- www/wordpress/Makefile			1.6
- www/wordpress/PLIST				1.4
- www/wordpress/distinfo			1.5
---
Module Name:    pkgsrc
Committed By:   adrianp
Date:           Thu Nov 12 22:05:55 UTC 2009

Modified Files:
        pkgsrc/www/wordpress: Makefile PLIST distinfo

Log Message:
Update to 2.8.6

- 2.8.5
* Fix for trackback DOS
* Removal of permalink_structure eval
* Remove some create_function() calls
* Disallow unfiltered uploads by default, even for admins. Enable it again with
define('ALLOW_UNFILTERED_UPLOADS', true); in wp-config.php
* Add extra escapes here and there for some backside coverage
* Retire two old importers
* A few small bug fixes

- 2.8.6
* Fixed an XSS vulnerability in Press This
* Fixed issue with sanitizing uploaded file names that can be exploited in
certain Apache configurations

Files:
RevisionActionfile
1.5.2.1modifypkgsrc/www/wordpress/Makefile
1.3.2.1modifypkgsrc/www/wordpress/PLIST
1.4.2.1modifypkgsrc/www/wordpress/distinfo