Re: [SECURITY] [DSA 2670-1] wordpress security update

2012-11-07 Thread Dominic Hargreaves
On Wed, Nov 07, 2012 at 10:39:15AM +0100, Raphael Hertzog wrote: > On Wed, 07 Nov 2012, Thijs Kinkhorst wrote: > > I think we should do this only when it has been shown that applying the > > fixes to the current version in stable(-security) is infeasible. Suppose > > now a simple XSS is discovered,

Re: [SECURITY] [DSA 2670-1] wordpress security update

2012-11-07 Thread Raphael Hertzog
On Wed, 07 Nov 2012, Thijs Kinkhorst wrote: > I think we should do this only when it has been shown that applying the > fixes to the current version in stable(-security) is infeasible. Suppose > now a simple XSS is discovered, I would be very much in favour to just > apply that fix. I would as wel

Re: [SECURITY] [DSA 2670-1] wordpress security update

2012-11-07 Thread Thijs Kinkhorst
On Wed, November 7, 2012 09:33, Raphael Hertzog wrote: >> Are there any plans to further upgrade squeeze in this manner? > > I leave this to Yves-Alexis... It would be nice to formalize this > approach with the security team. I think we should do this only when it has been shown that applying the

Re: [SECURITY] [DSA 2670-1] wordpress security update

2012-11-07 Thread Raphael Hertzog
Hi, On Tue, 06 Nov 2012, Dominic Hargreaves wrote: > On Fri, May 11, 2012 at 10:41:14PM +0200, Yves-Alexis Perez wrote: > > Several vulnerabilities were identified in Wordpress, a web blogging > > tool. As the CVEs were allocated from releases announcements and > > specific fixes are usually not

Re: [SECURITY] [DSA 2670-1] wordpress security update

2012-11-06 Thread Dominic Hargreaves
On Fri, May 11, 2012 at 10:41:14PM +0200, Yves-Alexis Perez wrote: > Several vulnerabilities were identified in Wordpress, a web blogging > tool. As the CVEs were allocated from releases announcements and > specific fixes are usually not identified, it has been decided to > upgrade the Wordpress p

Re: [SECURITY] [DSA 2670-1] wordpress security update

2012-05-12 Thread Cyril Brulebois
Marc Gorzala (11/05/2012): > auf c nutzen wir ja kein debian-wordpress Please set proper To/Cc fields and leave this list alone, thanks already. Mraw, KiBi. signature.asc Description: Digital signature

Re: [SECURITY] [DSA 2670-1] wordpress security update

2012-05-11 Thread Marc Gorzala
alle Maschinen aktualisiert. auf b ist wordpress immer noch drauf. wahrscheinlich unötiger Weise. Ich schaue morgen mal nach ob es doch genutzt wird. auf c schien das update schon eingespielt, von dir? gruß marc Am 11.05.2012 22:41, schrieb Yves-Alexis Perez: -BEGIN PGP SIGNED MESSAGE

Re: [SECURITY] [DSA 2670-1] wordpress security update

2012-05-11 Thread Marc Gorzala
Am 11.05.2012 23:01, schrieb Marc Gorzala: alle Maschinen aktualisiert. auf b ist wordpress immer noch drauf. wahrscheinlich unötiger Weise. Ich schaue morgen mal nach ob es doch genutzt wird. auf c schien das update schon eingespielt, von dir? auf c nutzen wir ja kein debian-wordpress gruß m