Path to this page:
Subject: CVS commit: [pkgsrc-2011Q1] pkgsrc/www/wordpress
From: Steven Drake
Date: 2011-05-27 13:07:01
Message id: 20110527110701.CAC59175DD@cvs.netbsd.org
Log Message:
Pullup ticket #3441 - requested by morr
www/wordpress security update
Revisions pulled up:
- www/wordpress/Makefile 1.19
- www/wordpress/distinfo 1.15
---
Module Name: pkgsrc
Committed By: morr
Date: Thu May 26 22:59:38 UTC 2011
Modified Files:
pkgsrc/www/wordpress: Makefile distinfo
Log Message:
Security update to 3.1.3.
* Various security hardening by Alexander Concha.
* Taxonomy query hardening by John Lamansky.
* Prevent sniffing out user names of non-authors by using canonical
redirects. Props VerĂ³nica Valeros.
* Media security fixes by Richard Lundeen of Microsoft, Jesse Ou of
Microsoft, and Microsoft Vulnerability Research.
* Improves file upload security on hosts with dangerous security
settings.
* Cleans up old WordPress import files if the import does not finish.
* Introduce "clickjacking" protection in modern browsers on admin and
login pages.
Files: