Subject: CVS commit: [pkgsrc-2014Q1] pkgsrc/www/wordpress
From: Matthias Scheler
Date: 2014-04-14 14:29:38
Message id: 20140414122938.286A496@cvs.netbsd.org

Log Message:
Pullup ticket #4370 - requested by morr
www/wordpress: security update

Revisions pulled up:
- www/wordpress/Makefile                                        1.39
- www/wordpress/distinfo                                        1.31

---
   Module Name:	pkgsrc
   Committed By:	morr
   Date:		Sun Apr 13 14:10:59 UTC 2014

   Modified Files:
   	pkgsrc/www/wordpress: Makefile distinfo

   Log Message:
   Update to newest version of Wordpress, containing security fixes.

   It contains 9 bugfixes and 5 security fixes:

   * Potential authentication cookie forgery. CVE-2014-0166.
   * Privilege escalation: prevent contributors from publishing posts. CVE-2014-0165.
   * (Hardening) Pass along additional information when processing pingbacks to \ 
help hosts identify potentially abusive requests.
   * (Hardening) Fix a low-impact SQL injection by trusted users.
   * (Hardening) Prevent possible cross-domain scripting through Plupload, the \ 
third-party library WordPress uses for uploading files.

Files:
RevisionActionfile
1.38.2.1modifypkgsrc/www/wordpress/Makefile
1.30.2.1modifypkgsrc/www/wordpress/distinfo