From 40e14d07c17ea2bf31c180aa3cce4bfa749d1b31 Mon Sep 17 00:00:00 2001 From: Jesse Keating Date: Wed, 17 Feb 2010 03:27:36 +0000 Subject: [PATCH 1/4] Initialize branch F-13 for wordpress-mu --- branch | 1 + 1 file changed, 1 insertion(+) create mode 100644 branch diff --git a/branch b/branch new file mode 100644 index 0000000..baa94ef --- /dev/null +++ b/branch @@ -0,0 +1 @@ +F-13 From 0dea7f8c749adccd6e0d4e75071522874368a3fb Mon Sep 17 00:00:00 2001 From: Fedora Release Engineering Date: Thu, 29 Jul 2010 15:23:57 +0000 Subject: [PATCH 2/4] dist-git conversion --- .cvsignore => .gitignore | 0 Makefile | 21 --------------------- branch | 1 - import.log | 1 - 4 files changed, 23 deletions(-) rename .cvsignore => .gitignore (100%) delete mode 100644 Makefile delete mode 100644 branch delete mode 100644 import.log diff --git a/.cvsignore b/.gitignore similarity index 100% rename from .cvsignore rename to .gitignore diff --git a/Makefile b/Makefile deleted file mode 100644 index 58736f5..0000000 --- a/Makefile +++ /dev/null @@ -1,21 +0,0 @@ -# Makefile for source rpm: wordpress-mu -# $Id: Makefile,v 1.1 2008/08/25 19:55:16 kevin Exp $ -NAME := wordpress-mu -SPECFILE = $(firstword $(wildcard *.spec)) - -define find-makefile-common -for d in common ../common ../../common ; do if [ -f $$d/Makefile.common ] ; then if [ -f $$d/CVS/Root -a -w $$d/Makefile.common ] ; then cd $$d ; cvs -Q update ; fi ; echo "$$d/Makefile.common" ; break ; fi ; done -endef - -MAKEFILE_COMMON := $(shell $(find-makefile-common)) - -ifeq ($(MAKEFILE_COMMON),) -# attept a checkout -define checkout-makefile-common -test -f CVS/Root && { cvs -Q -d $$(cat CVS/Root) checkout common && echo "common/Makefile.common" ; } || { echo "ERROR: I can't figure out how to checkout the 'common' module." ; exit -1 ; } >&2 -endef - -MAKEFILE_COMMON := $(shell $(checkout-makefile-common)) -endif - -include $(MAKEFILE_COMMON) diff --git a/branch b/branch deleted file mode 100644 index baa94ef..0000000 --- a/branch +++ /dev/null @@ -1 +0,0 @@ -F-13 diff --git a/import.log b/import.log deleted file mode 100644 index 83b639a..0000000 --- a/import.log +++ /dev/null @@ -1 +0,0 @@ -wordpress-mu-2_6_1-1_fc8:HEAD:wordpress-mu-2.6.1-1.fc8.src.rpm:1220452323 From 994da414a432d09814c7914c06d326f0e56bfe91 Mon Sep 17 00:00:00 2001 From: Jon Ciesla Date: Mon, 3 Jan 2011 12:41:50 -0600 Subject: [PATCH 3/4] Retiring. --- README.fedora.wordpress-mu | 20 ---- dead.package | 2 + sources | 1 - wordpress-mu-2.9.2-r16625.patch | 9 -- wordpress-mu-httpd-conf | 25 ----- wordpress-mu.spec | 163 -------------------------------- 6 files changed, 2 insertions(+), 218 deletions(-) delete mode 100644 README.fedora.wordpress-mu create mode 100644 dead.package delete mode 100644 sources delete mode 100644 wordpress-mu-2.9.2-r16625.patch delete mode 100644 wordpress-mu-httpd-conf delete mode 100644 wordpress-mu.spec diff --git a/README.fedora.wordpress-mu b/README.fedora.wordpress-mu deleted file mode 100644 index 2fba019..0000000 --- a/README.fedora.wordpress-mu +++ /dev/null @@ -1,20 +0,0 @@ -Alias /wordpress-mu /usr/share/wordpress-mu - - - AllowOverride Options - RewriteEngine On - - RewriteBase /wordpress-mu/ - - #uploaded files - RewriteRule ^(.*/)?files/$ index.php [L] - RewriteRule ^(.*/)?files/(.*) wp-content/blogs.php?file=$2 [L] - - RewriteCond %{REQUEST_FILENAME} -f [OR] - RewriteCond %{REQUEST_FILENAME} -d - RewriteRule . - [L] - RewriteRule ^([_0-9a-zA-Z-]+/)?(wp-.*) $2 [L] - RewriteRule ^([_0-9a-zA-Z-]+/)?(.*\.php)$ $2 [L] - RewriteRule . index.php [L] - - diff --git a/dead.package b/dead.package new file mode 100644 index 0000000..9caa2aa --- /dev/null +++ b/dead.package @@ -0,0 +1,2 @@ +Deprecated by upstream as of wordpress 3.0.x. Obsoleted by wordpress +package, which now includes a README on migrating from -mu. diff --git a/sources b/sources deleted file mode 100644 index d402cca..0000000 --- a/sources +++ /dev/null @@ -1 +0,0 @@ -3dff1dd886414ef80ffddba7a33172bf wordpress-mu-2.9.2.tar.gz diff --git a/wordpress-mu-2.9.2-r16625.patch b/wordpress-mu-2.9.2-r16625.patch deleted file mode 100644 index 38cff4b..0000000 --- a/wordpress-mu-2.9.2-r16625.patch +++ /dev/null @@ -1,9 +0,0 @@ ---- wp-includes/comment.php~ 2009-12-21 11:46:30.000000000 -0600 -+++ wp-includes/comment.php 2010-12-23 09:35:38.596027997 -0600 -@@ -1590,5 +1590,5 @@ - $pinged[] = $tb_ping; - } else { -- $wpdb->query( $wpdb->prepare("UPDATE $wpdb->posts SET to_ping = TRIM(REPLACE(to_ping, '$tb_ping', '')) WHERE ID = %d", $post_id) ); -+ $wpdb->query( $wpdb->prepare("UPDATE $wpdb->posts SET to_ping = TRIM(REPLACE(to_ping, %s, '')) WHERE ID = %d", $tb_ping, $post_id) ); - } - } diff --git a/wordpress-mu-httpd-conf b/wordpress-mu-httpd-conf deleted file mode 100644 index 49685e8..0000000 --- a/wordpress-mu-httpd-conf +++ /dev/null @@ -1,25 +0,0 @@ -Alias /wordpress-mu /usr/share/wordpress-mu - - - AllowOverride Options - RewriteEngine On - - RewriteBase /wordpress-mu/ - - #uploaded files - RewriteRule ^(.*/)?files/$ index.php [L] - RewriteCond %{REQUEST_URI} !.*wp-content/plugins.* - RewriteRule ^(.*/)?files/(.*) wp-content/blogs.php?file=$2 [L] - - # add a trailing slash to /wp-admin - RewriteCond %{REQUEST_URI} ^.*/wp-admin$ - RewriteRule ^(.+)$ $1/ [R=301,L] - - RewriteCond %{REQUEST_FILENAME} -f [OR] - RewriteCond %{REQUEST_FILENAME} -d - RewriteRule . - [L] - RewriteRule ^([_0-9a-zA-Z-]+/)?(wp-.*) $2 [L] - RewriteRule ^([_0-9a-zA-Z-]+/)?(.*\.php)$ $2 [L] - RewriteRule . index.php [L] - - diff --git a/wordpress-mu.spec b/wordpress-mu.spec deleted file mode 100644 index 9a072c5..0000000 --- a/wordpress-mu.spec +++ /dev/null @@ -1,163 +0,0 @@ -Summary: WordPress-MU multi-user blogging software -URL: http://mu.wordpress.org/latest.tar.gz -Name: wordpress-mu -Version: 2.9.2 -Release: 2%{?dist} -Group: Applications/Publishing -License: GPLv2 -Source0: %{name}-%{version}.tar.gz -Source1: wordpress-mu-httpd-conf -Source2: README.fedora.wordpress-mu -Patch0: wordpress-mu-2.9.2-r16625.patch -BuildRoot: %{_tmppath}/%{name}-%{version}-%{release}-root-%(%{__id_u} -n) -Requires: php >= 4.1.0, webserver, php-mysql -BuildArch: noarch - -%description -WordPress-MU is a derivative of the WordPress blogging codebase, to allow -one instance to serve multiple users. - -%prep -%setup -q -n wordpress-mu - -%patch0 -p0 -b .16625 - -# disable-wordpress-core-update, updates are always installed via rpm -# -# the sed script from wordpress.spec doesn't work due to if/else statement in upstream wordpress-mu's update.php -# sed -i -e "s,add_action,#add_action,g" wp-includes/update.php - -echo "" > wp-includes/update.php - -%build - - -%install -rm -rf %{buildroot} - -mkdir -p %{buildroot}%{_datadir}/wordpress-mu -mkdir -p %{buildroot}%{_sysconfdir}/wordpress-mu -install -m 0644 -D -p %{SOURCE1} %{buildroot}%{_sysconfdir}/httpd/conf.d/wordpress-mu.conf -install -m 0644 -D -p %{SOURCE2} %{buildroot}%{_docdir}/%{name}-%{version}/README.fedora - -cp -pr * %{buildroot}%{_datadir}/wordpress-mu - -# fix weird upstream perms... -chmod 0644 %{buildroot}%{_datadir}/wordpress-mu/wp-includes/js/tinymce/plugins/spellchecker/css/content.css -chmod 0664 %{buildroot}%{_datadir}/wordpress-mu/wp-includes/js/tinymce/plugins/spellchecker/editor_plugin.js -chmod 0664 %{buildroot}%{_datadir}/wordpress-mu/wp-includes/js/tinymce/plugins/spellchecker/config.php - - -# since we're using /etc/httpd/conf.d, don't do the funky .htaccess stuff -# that the installer wants -echo "# please see /etc/httpd/conf.d/wordpress-mu.conf" > %{buildroot}%{_datadir}/wordpress-mu/htaccess.dist - - -# Remove empty files to make rpmlint happy -find %{buildroot} -empty -exec rm -f {} \; -# These are docs, remove them from here, docify them later -rm -f %{buildroot}%{_datadir}/wordpress-mu/{license.txt,README.txt} -# remove these as well, detritus -rm -f %{buildroot}%{_datadir}/wordpress-mu/{wordpress-mu-httpd-conf,README.fedora} - - -%clean -rm -rf %{buildroot} - -%files -%defattr(-,root,root,-) -%config(noreplace) %{_sysconfdir}/httpd/conf.d/wordpress-mu.conf -%dir %{_datadir}/wordpress-mu -%{_datadir}/wordpress-mu/htaccess.dist -%{_datadir}/wordpress-mu/wp-admin -%{_datadir}/wordpress-mu/wp-content -%{_datadir}/wordpress-mu/wp-includes -%{_datadir}/wordpress-mu/index.php -%doc license.txt -%doc README.txt -%{_datadir}/wordpress-mu/index-install.php -%{_datadir}/wordpress-mu/wp-activate.php -%{_datadir}/wordpress-mu/wp-atom.php -%{_datadir}/wordpress-mu/wp-app.php -%{_datadir}/wordpress-mu/wp-blog-header.php -%{_datadir}/wordpress-mu/wp-comments-post.php -%{_datadir}/wordpress-mu/wp-commentsrss2.php -%{_datadir}/wordpress-mu/wp-config-sample.php -%{_datadir}/wordpress-mu/wp-cron.php -%{_datadir}/wordpress-mu/wp-feed.php -%{_datadir}/wordpress-mu/wp-load.php -%{_datadir}/wordpress-mu/wp-links-opml.php -%{_datadir}/wordpress-mu/wp-login.php -%{_datadir}/wordpress-mu/wp-mail.php -%{_datadir}/wordpress-mu/wp-pass.php -%{_datadir}/wordpress-mu/wp-rdf.php -%{_datadir}/wordpress-mu/wp-register.php -%{_datadir}/wordpress-mu/wp-rss.php -%{_datadir}/wordpress-mu/wp-rss2.php -%{_datadir}/wordpress-mu/wp-settings.php -%{_datadir}/wordpress-mu/wpmu-settings.php -%{_datadir}/wordpress-mu/wp-signup.php -%{_datadir}/wordpress-mu/wp-trackback.php -%{_datadir}/wordpress-mu/xmlrpc.php -%dir %{_sysconfdir}/wordpress-mu - -%changelog -* Thu Dec 23 2010 Jon Ciesla - 2.9.2-2 -- Change Requires from httpd to webserver, BZ 523480. -- Patch for security vulnerability, BZ 659319. - -* Mon May 10 2010 Bret McMillan - 2.9.2-1 -- updating to 2.9.2 - -* Fri Jan 29 2010 Bret McMillan - 2.9.1.1-1 -- collected bug fixes and enhancements from wordpress 2.9.x merged into wpmu 2.9.1 -- Plugins options fix: http://trac.mu.wordpress.org/ticket/1193 -- wp_getUserBlogs fix: http://trac.mu.wordpress.org/ticket/1195 - -* Mon Nov 30 2009 Bret McMillan - 2.8.6-1 -- update to 2.8.6; couple of security fixes, including 1 XSS - -* Fri Nov 6 2009 Bret McMillan - 2.8.5.2-1 -- Update to version 2.8.5.2 for security fixes - -* Wed Aug 12 2009 Bret McMillan - 2.8.4a-1 -- Update to version 2.8.4a for security fixes - -* Thu Jul 30 2009 Bret McMillan - 2.7-8 -- fix backported for 2.8.2 comment author XSS vulnerability - -* Fri Jul 10 2009 Bret McMillan - 2.7-6 -- Patch for CVE-2009-2334 - -* Wed Feb 25 2009 Fedora Release Engineering - 2.7-5 -- Rebuilt for https://fedoraproject.org/wiki/Fedora_11_Mass_Rebuild - -* Thu Feb 12 2009 Bret McMillan - 2.7-4 -- Update to version 2.7 -- Alter source prep so I can still use upstream's tarball -- favicon.ico removed from manifest - -* Mon Dec 1 2008 Bret McMillan - 2.6.5-1 -- Update to 2.6.5 -- http://wordpress.org/development/2008/11/wordpress-265/ -- http://ocaoimh.ie/2008/11/25/wordpress-mu-265/ -- Fixes 1 XSS security issue, 3 bugs - -* Wed Sep 3 2008 Bret McMillan - 2.6.1-1 -- update to 2.6.1 - -* Tue Jul 29 2008 Bret McMillan - 2.6-7 -- added build section to the spec file - -* Wed Jul 29 2008 Bret McMillan - 2.6-6 -- rebasing to wpmu 2.6 - -* Fri May 30 2008 Bret McMillan - 1.5.1-2 -- trying to clean up how we're dealing with htaccess.dist - -* Mon May 26 2008 Bret McMillan - 1.5.1-1 -- update to 1.5.1; getting ready for Fedora submission - -* Fri Apr 25 2008 Bret McMillan - 1.3.3-1 -- initial version; copying heuristics from the base fedora wordpress pkg - From 97c4082295f4b24b8fc01fd11481a93143a96e60 Mon Sep 17 00:00:00 2001 From: Jon Ciesla Date: Tue, 11 Jan 2011 11:44:28 -0600 Subject: [PATCH 4/4] Security fixes. --- wordpress-mu-2.9.2-r17172.patch | 92 +++++++++++++++++++++++++++++++++ wordpress-mu.spec | 7 ++- 2 files changed, 98 insertions(+), 1 deletion(-) create mode 100644 wordpress-mu-2.9.2-r17172.patch diff --git a/wordpress-mu-2.9.2-r17172.patch b/wordpress-mu-2.9.2-r17172.patch new file mode 100644 index 0000000..b78b7ae --- /dev/null +++ b/wordpress-mu-2.9.2-r17172.patch @@ -0,0 +1,92 @@ +diff -r -U2 wordpress.orig/wp-includes/formatting.php wordpress/wp-includes/formatting.php +--- wordpress.orig/wp-includes/formatting.php 2009-11-11 17:10:13.000000000 -0600 ++++ wordpress/wp-includes/formatting.php 2011-01-11 10:34:13.970920002 -0600 +@@ -2092,6 +2092,7 @@ + // Replace ampersands and single quotes only when displaying. + if ( 'display' == $context ) { +- $url = preg_replace('/&([^#])(?![a-z]{2,8};)/', '&$1', $url); +- $url = str_replace( "'", ''', $url ); ++ $url = wp_kses_normalize_entities( $url ); ++ $url = str_replace( '&', '&', $url ); ++ $url = str_replace( "'", ''', $url ); + } + +diff -r -U2 wordpress.orig/wp-includes/kses.php wordpress/wp-includes/kses.php +--- wordpress.orig/wp-includes/kses.php 2009-07-08 04:53:22.000000000 -0500 ++++ wordpress/wp-includes/kses.php 2011-01-11 10:47:04.468920001 -0600 +@@ -534,5 +534,5 @@ + } + +- if ( $arreach['name'] == 'style' ) { ++ if ( strtolower($arreach['name']) == 'style' ) { + $orig_value = $arreach['value']; + +@@ -626,5 +626,5 @@ + { + $thisval = $match[1]; +- if ( in_array($attrname, $uris) ) ++ if ( in_array(strtolower($attrname), $uris) ) + $thisval = wp_kses_bad_protocol($thisval, $allowed_protocols); + +@@ -642,5 +642,5 @@ + { + $thisval = $match[1]; +- if ( in_array($attrname, $uris) ) ++ if ( in_array(strtolower($attrname), $uris) ) + $thisval = wp_kses_bad_protocol($thisval, $allowed_protocols); + +@@ -658,5 +658,5 @@ + { + $thisval = $match[1]; +- if ( in_array($attrname, $uris) ) ++ if ( in_array(strtolower($attrname), $uris) ) + $thisval = wp_kses_bad_protocol($thisval, $allowed_protocols); + +@@ -882,12 +882,7 @@ + */ + function wp_kses_bad_protocol_once($string, $allowed_protocols) { +- global $_kses_allowed_protocols; +- $_kses_allowed_protocols = $allowed_protocols; +- +- $string2 = preg_split('/:|:|:/i', $string, 2); +- if ( isset($string2[1]) && !preg_match('%/\?%', $string2[0]) ) +- $string = wp_kses_bad_protocol_once2($string2[0]) . trim($string2[1]); +- else +- $string = preg_replace_callback('/^((&[^;]*;|[\sA-Za-z0-9])*)'.'(:|:|&#[Xx]3[Aa];)\s*/', 'wp_kses_bad_protocol_once2', $string); ++ $string2 = preg_split( '/:|�*58;|�*3a;/i', $string, 2 ); ++ if ( isset($string2[1]) && ! preg_match('%/\?%', $string2[0]) ) ++ $string = wp_kses_bad_protocol_once2( $string2[0], $allowed_protocols ) . trim( $string2[1] ); + + return $string; +@@ -903,19 +898,9 @@ + * @since 1.0.0 + * +- * @param mixed $matches string or preg_replace_callback() matches array to check for bad protocols ++ * @param string $string URI scheme to check against the whitelist ++ * @param string $allowed_protocols Allowed protocols + * @return string Sanitized content + */ +-function wp_kses_bad_protocol_once2($matches) { +- global $_kses_allowed_protocols; +- +- if ( is_array($matches) ) { +- if ( ! isset($matches[1]) || empty($matches[1]) ) +- return ''; +- +- $string = $matches[1]; +- } else { +- $string = $matches; +- } +- ++function wp_kses_bad_protocol_once2( $string, $allowed_protocols ) { + $string2 = wp_kses_decode_entities($string); + $string2 = preg_replace('/\s/', '', $string2); +@@ -926,6 +911,6 @@ + + $allowed = false; +- foreach ( (array) $_kses_allowed_protocols as $one_protocol) +- if (strtolower($one_protocol) == $string2) { ++ foreach ( (array) $allowed_protocols as $one_protocol ) ++ if ( strtolower($one_protocol) == $string2 ) { + $allowed = true; + break; diff --git a/wordpress-mu.spec b/wordpress-mu.spec index 9a072c5..553378b 100644 --- a/wordpress-mu.spec +++ b/wordpress-mu.spec @@ -2,13 +2,14 @@ Summary: WordPress-MU multi-user blogging software URL: http://mu.wordpress.org/latest.tar.gz Name: wordpress-mu Version: 2.9.2 -Release: 2%{?dist} +Release: 3%{?dist} Group: Applications/Publishing License: GPLv2 Source0: %{name}-%{version}.tar.gz Source1: wordpress-mu-httpd-conf Source2: README.fedora.wordpress-mu Patch0: wordpress-mu-2.9.2-r16625.patch +Patch1: wordpress-mu-2.9.2-r17172.patch BuildRoot: %{_tmppath}/%{name}-%{version}-%{release}-root-%(%{__id_u} -n) Requires: php >= 4.1.0, webserver, php-mysql BuildArch: noarch @@ -21,6 +22,7 @@ one instance to serve multiple users. %setup -q -n wordpress-mu %patch0 -p0 -b .16625 +%patch1 -p1 -b .17172 # disable-wordpress-core-update, updates are always installed via rpm # @@ -102,6 +104,9 @@ rm -rf %{buildroot} %dir %{_sysconfdir}/wordpress-mu %changelog +* Tue Jan 11 2011 Jon Ciesla - 2.9.2-3 +- Patches for security flaws, BZ 668192. + * Thu Dec 23 2010 Jon Ciesla - 2.9.2-2 - Change Requires from httpd to webserver, BZ 523480. - Patch for security vulnerability, BZ 659319.