[Date Prev][Date Next] [Thread Prev][Thread Next] [Date Index] [Thread Index]

Re: [SECURITY] [DSA 3870-1] wordpress security update



On Mon, Jun 05, 2017 at 08:40:12PM +0200, Paul Gevers wrote:
> Hi Rodrigo,
> 
> On 05-06-17 20:30, Rodrigo Campos wrote:
> > On Mon, Jun 05, 2017 at 08:16:09PM +0200, Paul Gevers wrote:
> >> On 05-06-17 20:14, Rodrigo Campos wrote:
> >>> On Mon, Jun 05, 2017 at 07:56:49PM +0200, Paul Gevers wrote:
> >>>> I don't want to push, but how about upgrading wordpress in backports? Is
> >>>> there any problem with (me) just uploading the latest version in stretch?
> >>>
> >>> The build was done on the same day wordpress announced it, but there is a
> >>> problem with Craig keys and it wasn't uploaded.
> >>>
> >>> It will hopefully be uploaded soon. Sorry for the inconvenience, I did it as
> >>> fast I can, but the keys issue was unexpected :-/
> >>
> >> Anything I can do to help?
> > 
> > Don't think so :-/
> > 
> > What is missing is a security number and, if keys issue is resolved, just being
> > uploaded to jessie-backports.
> 
> When I read this, I thought "weird, I saw the DSA, so what do you
> mean?", but...
> 
> > Also, the package is on mentors, so you can use that in the meantime if you
> > prefer. The package uploaded to sid today is there, too.
> 
> I now see there is a -2 package. Didn't notice that until this e-mail.

No, I didn't mean that. I mean:
https://backports.debian.org/Contribute/#index3h2

We need (or Craig, that is the sponsor) to ask for a BSA. The DSA doesn't apply
for backports :)

> Anyways, personally I can wait a couple of days, just didn't want to see
> stuff like this fall through any crack.

Thanks :)

> 
> > Craig, when you have some time, please ask for a security number and upload to
> > jessie-backports as usual. Or let us know if there is anything we can do to help :)
> 
> I'll let you handle it then. Don't hesitate to call for help if you need
> it though.


Thanks again! :)


Reply to: