Subject: CVS commit: [pkgsrc-2018Q2] pkgsrc/www/wordpress
From: Benny Siegert
Date: 2018-07-16 16:04:22
Message id: 20180716140422.7B317FBEC@cvs.NetBSD.org

Log Message:
Pullup ticket #5786 - requested by taca
www/wordpress: security fix

Revisions pulled up:
- www/wordpress/Makefile                                        1.79-1.80
- www/wordpress/distinfo                                        1.64

---
   Module Name:	pkgsrc
   Committed By:	jperkin
   Date:		Wed Jul  4 13:40:45 UTC 2018

   Modified Files:
   	pkgsrc/www/wordpress: Makefile

   Log Message:
   *: Move SUBST_STAGE from post-patch to pre-configure

   Performing substitutions during post-patch breaks tools such as mkpatches,
   making it very difficult to regenerate correct patches after making changes,
   and often leading to substituted string replacements being committed.

---
   Module Name:	pkgsrc
   Committed By:	wen
   Date:		Sat Jul  7 02:55:25 UTC 2018

   Modified Files:
   	pkgsrc/www/wordpress: Makefile distinfo

   Log Message:
   Update to 4.9.7

   Upstream changes:
   WordPress 4.9.7 is now available. This is a security and maintenance release \ 
for all versions since WordPress 3.7. We strongly encourage you to update your \ 
sites immediately.

   WordPress versions 4.9.6 and earlier are affected by a media issue that could \ 
potentially allow a user with certain capabilities to attempt to delete files \ 
outside the uploads directory.

   Thank you to Slavco for reporting the original issue and Matt Barry for \ 
reporting related issues.

   Seventeen other bugs were fixed in WordPress 4.9.7. Particularly of note were:

       Taxonomy: Improve cache handling for term queries.
       Posts, Post Types: Clear post password cookie when logging out.
       Widgets: Allow basic HTML tags in sidebar descriptions on Widgets admin \ 
screen.
       Community Events Dashboard: Always show the nearest WordCamp if one is \ 
coming up, even if there are multiple Meetups happening first.
       Privacy: Make sure default privacy policy content does not cause a fatal \ 
error when flushing rewrite rules outside of the admin context.

Files:
RevisionActionfile
1.78.2.1modifypkgsrc/www/wordpress/Makefile
1.63.2.1modifypkgsrc/www/wordpress/distinfo