From 9c954c402f803119efbeced4ac97e9e66bf4149e Mon Sep 17 00:00:00 2001 From: Jesse Keating Date: Wed, 17 Feb 2010 03:27:35 +0000 Subject: [PATCH 01/21] Initialize branch F-13 for wordpress --- branch | 1 + 1 file changed, 1 insertion(+) create mode 100644 branch diff --git a/branch b/branch new file mode 100644 index 0000000..baa94ef --- /dev/null +++ b/branch @@ -0,0 +1 @@ +F-13 From 66439e29b81d980b883ca0674be9112b7e869eb8 Mon Sep 17 00:00:00 2001 From: Fedora Release Engineering Date: Thu, 29 Jul 2010 15:23:41 +0000 Subject: [PATCH 02/21] dist-git conversion --- .cvsignore => .gitignore | 0 Makefile | 21 --------------------- branch | 1 - 3 files changed, 22 deletions(-) rename .cvsignore => .gitignore (100%) delete mode 100644 Makefile delete mode 100644 branch diff --git a/.cvsignore b/.gitignore similarity index 100% rename from .cvsignore rename to .gitignore diff --git a/Makefile b/Makefile deleted file mode 100644 index f25a67e..0000000 --- a/Makefile +++ /dev/null @@ -1,21 +0,0 @@ -# Makefile for source rpm: wordpress -# $Id$ -NAME := wordpress -SPECFILE = $(firstword $(wildcard *.spec)) - -define find-makefile-common -for d in common ../common ../../common ; do if [ -f $$d/Makefile.common ] ; then if [ -f $$d/CVS/Root -a -w $$d/Makefile.common ] ; then cd $$d ; cvs -Q update ; fi ; echo "$$d/Makefile.common" ; break ; fi ; done -endef - -MAKEFILE_COMMON := $(shell $(find-makefile-common)) - -ifeq ($(MAKEFILE_COMMON),) -# attept a checkout -define checkout-makefile-common -test -f CVS/Root && { cvs -Q -d $$(cat CVS/Root) checkout common && echo "common/Makefile.common" ; } || { echo "ERROR: I can't figure out how to checkout the 'common' module." ; exit -1 ; } >&2 -endef - -MAKEFILE_COMMON := $(shell $(checkout-makefile-common)) -endif - -include $(MAKEFILE_COMMON) diff --git a/branch b/branch deleted file mode 100644 index baa94ef..0000000 --- a/branch +++ /dev/null @@ -1 +0,0 @@ -F-13 From 8ff4ce2bdf8358be888c8ef9bfd56da61a323a54 Mon Sep 17 00:00:00 2001 From: Jon Ciesla Date: Thu, 23 Dec 2010 09:02:21 -0600 Subject: [PATCH 03/21] Multiple fixes. --- wordpress-2.8.6-r16625.patch | 11 +++++ wordpress-debian_patches_hello.patch | 60 ++++++++++++++++++++++++++++ wordpress.spec | 15 ++++++- 3 files changed, 84 insertions(+), 2 deletions(-) create mode 100644 wordpress-2.8.6-r16625.patch create mode 100644 wordpress-debian_patches_hello.patch diff --git a/wordpress-2.8.6-r16625.patch b/wordpress-2.8.6-r16625.patch new file mode 100644 index 0000000..a373f85 --- /dev/null +++ b/wordpress-2.8.6-r16625.patch @@ -0,0 +1,11 @@ +--- wp-includes/comment.php~ 2009-07-21 18:10:34.000000000 -0500 ++++ wp-includes/comment.php 2010-12-23 08:55:05.433027996 -0600 +@@ -1365,7 +1365,7 @@ + trackback($tb_ping, $post_title, $excerpt, $post_id); + $pinged[] = $tb_ping; + } else { +- $wpdb->query( $wpdb->prepare("UPDATE $wpdb->posts SET to_ping = TRIM(REPLACE(to_ping, '$tb_ping', '')) WHERE ID = %d", $post_id) ); ++ $wpdb->query( $wpdb->prepare("UPDATE $wpdb->posts SET to_ping = TRIM(REPLACE(to_ping, %s, '')) WHERE ID = %d", $tb_ping, $post_id) ); + } + } + } diff --git a/wordpress-debian_patches_hello.patch b/wordpress-debian_patches_hello.patch new file mode 100644 index 0000000..7e52551 --- /dev/null +++ b/wordpress-debian_patches_hello.patch @@ -0,0 +1,60 @@ +Use GPL-compliant lyrics in the hello dolly plugin +--- a/wp-content/plugins/hello.php ++++ b/wp-content/plugins/hello.php +@@ -6,42 +6,26 @@ + /* + Plugin Name: Hello Dolly + Plugin URI: http://wordpress.org/# +-Description: This is not just a plugin, it symbolizes the hope and enthusiasm of an entire generation summed up in two words sung most famously by Louis Armstrong: Hello, Dolly. When activated you will randomly see a lyric from Hello, Dolly in the upper right of your admin screen on every page. ++Description: This is not just a plugin, it symbolizes the hope and enthusiasm of an entire generation summed up in two words sung most famously by Richard M. Stallman: Free Software. When activated you will randomly see a lyric from the Free Software Song in the upper right of your admin screen on every page. + Author: Matt Mullenweg + Version: 1.5.1 + Author URI: http://ma.tt/ + */ + + function hello_dolly_get_lyric() { +- /** These are the lyrics to Hello Dolly */ +- $lyrics = "Hello, Dolly +-Well, hello, Dolly +-It's so nice to have you back where you belong +-You're lookin' swell, Dolly +-I can tell, Dolly +-You're still glowin', you're still crowin' +-You're still goin' strong +-We feel the room swayin' +-While the band's playin' +-One of your old favourite songs from way back when +-So, take her wrap, fellas +-Find her an empty lap, fellas +-Dolly'll never go away again +-Hello, Dolly +-Well, hello, Dolly +-It's so nice to have you back where you belong +-You're lookin' swell, Dolly +-I can tell, Dolly +-You're still glowin', you're still crowin' +-You're still goin' strong +-We feel the room swayin' +-While the band's playin' +-One of your old favourite songs from way back when +-Golly, gee, fellas +-Find her a vacant knee, fellas +-Dolly'll never go away +-Dolly'll never go away +-Dolly'll never go away again"; ++ // These are the lyrics to the Free Software Song ++$lyrics = "Join us now and share the software; ++You'll be free, hackers, you'll be free. ++Hoarders may get piles of money, ++That is true, hackers, that is true. ++But they cannot help their neighbors; ++That ain't good, hackers, that ain't good. ++When we have enough free software ++At our call, hackers, at our call, ++We'll kick out those dirty licenses ++Ever more, hackers, ever more. ++Join us now and share the software; ++You'll be free, hackers, you'll be free."; + + // Here we split it into lines + $lyrics = explode("\n", $lyrics); diff --git a/wordpress.spec b/wordpress.spec index 31788b0..e3d1adf 100644 --- a/wordpress.spec +++ b/wordpress.spec @@ -3,13 +3,15 @@ URL: http://www.wordpress.org Name: wordpress Version: 2.8.6 Group: Applications/Publishing -Release: 2%{?dist} +Release: 3%{?dist} License: GPLv2 Source0: http://wordpress.org/%{name}-%{version}.tar.gz Source1: wordpress-httpd-conf Source2: README.fedora.wordpress +Patch0: wordpress-2.8.6-r16625.patch +Patch1: wordpress-debian_patches_hello.patch BuildRoot: %{_tmppath}/%{name}-%{version}-%{release}-root-%(%{__id_u} -n) -Requires: php >= 4.1.0, httpd, php-mysql +Requires: php >= 4.1.0, webserver, php-mysql BuildArch: noarch %description @@ -18,6 +20,10 @@ almost trivial, to get information out to people on the web. %prep %setup -q -n wordpress + +%patch0 -p0 -b .16625 +%patch1 -p1 -b .dolly + # disable wp_version_check, updates are always installed via rpm sed -i -e "s,\(.*\)'wp_version_check'\(.*\),#\1'wp_version_check'\2,g" \ wp-includes/update.php @@ -81,6 +87,11 @@ rm -rf ${RPM_BUILD_ROOT} %dir %{_sysconfdir}/wordpress %changelog +* Thu Dec 23 2010 Jon Ciesla - 2.8.6-3 +- Change Requires from httpd to webserver, BZ 523480. +- Patch for Hello Dolly lyrics, BZ 663966. +- Patch for security vulnerability, BZ 659319. + * Mon Nov 16 2009 Adrian Reber - 2.8.6-2 - updated to 2.8.6 (Security Release) From 498511599be3000ff2bea796c05aafbc8bd316e6 Mon Sep 17 00:00:00 2001 From: Jon Ciesla Date: Tue, 11 Jan 2011 10:55:45 -0600 Subject: [PATCH 04/21] Fix for BZ 666782. --- wordpress-2.8.6-r17172.patch | 92 ++++++++++++++++++++++++++++++++++++ wordpress.spec | 8 +++- 2 files changed, 99 insertions(+), 1 deletion(-) create mode 100644 wordpress-2.8.6-r17172.patch diff --git a/wordpress-2.8.6-r17172.patch b/wordpress-2.8.6-r17172.patch new file mode 100644 index 0000000..b78b7ae --- /dev/null +++ b/wordpress-2.8.6-r17172.patch @@ -0,0 +1,92 @@ +diff -r -U2 wordpress.orig/wp-includes/formatting.php wordpress/wp-includes/formatting.php +--- wordpress.orig/wp-includes/formatting.php 2009-11-11 17:10:13.000000000 -0600 ++++ wordpress/wp-includes/formatting.php 2011-01-11 10:34:13.970920002 -0600 +@@ -2092,6 +2092,7 @@ + // Replace ampersands and single quotes only when displaying. + if ( 'display' == $context ) { +- $url = preg_replace('/&([^#])(?![a-z]{2,8};)/', '&$1', $url); +- $url = str_replace( "'", ''', $url ); ++ $url = wp_kses_normalize_entities( $url ); ++ $url = str_replace( '&', '&', $url ); ++ $url = str_replace( "'", ''', $url ); + } + +diff -r -U2 wordpress.orig/wp-includes/kses.php wordpress/wp-includes/kses.php +--- wordpress.orig/wp-includes/kses.php 2009-07-08 04:53:22.000000000 -0500 ++++ wordpress/wp-includes/kses.php 2011-01-11 10:47:04.468920001 -0600 +@@ -534,5 +534,5 @@ + } + +- if ( $arreach['name'] == 'style' ) { ++ if ( strtolower($arreach['name']) == 'style' ) { + $orig_value = $arreach['value']; + +@@ -626,5 +626,5 @@ + { + $thisval = $match[1]; +- if ( in_array($attrname, $uris) ) ++ if ( in_array(strtolower($attrname), $uris) ) + $thisval = wp_kses_bad_protocol($thisval, $allowed_protocols); + +@@ -642,5 +642,5 @@ + { + $thisval = $match[1]; +- if ( in_array($attrname, $uris) ) ++ if ( in_array(strtolower($attrname), $uris) ) + $thisval = wp_kses_bad_protocol($thisval, $allowed_protocols); + +@@ -658,5 +658,5 @@ + { + $thisval = $match[1]; +- if ( in_array($attrname, $uris) ) ++ if ( in_array(strtolower($attrname), $uris) ) + $thisval = wp_kses_bad_protocol($thisval, $allowed_protocols); + +@@ -882,12 +882,7 @@ + */ + function wp_kses_bad_protocol_once($string, $allowed_protocols) { +- global $_kses_allowed_protocols; +- $_kses_allowed_protocols = $allowed_protocols; +- +- $string2 = preg_split('/:|:|:/i', $string, 2); +- if ( isset($string2[1]) && !preg_match('%/\?%', $string2[0]) ) +- $string = wp_kses_bad_protocol_once2($string2[0]) . trim($string2[1]); +- else +- $string = preg_replace_callback('/^((&[^;]*;|[\sA-Za-z0-9])*)'.'(:|:|&#[Xx]3[Aa];)\s*/', 'wp_kses_bad_protocol_once2', $string); ++ $string2 = preg_split( '/:|�*58;|�*3a;/i', $string, 2 ); ++ if ( isset($string2[1]) && ! preg_match('%/\?%', $string2[0]) ) ++ $string = wp_kses_bad_protocol_once2( $string2[0], $allowed_protocols ) . trim( $string2[1] ); + + return $string; +@@ -903,19 +898,9 @@ + * @since 1.0.0 + * +- * @param mixed $matches string or preg_replace_callback() matches array to check for bad protocols ++ * @param string $string URI scheme to check against the whitelist ++ * @param string $allowed_protocols Allowed protocols + * @return string Sanitized content + */ +-function wp_kses_bad_protocol_once2($matches) { +- global $_kses_allowed_protocols; +- +- if ( is_array($matches) ) { +- if ( ! isset($matches[1]) || empty($matches[1]) ) +- return ''; +- +- $string = $matches[1]; +- } else { +- $string = $matches; +- } +- ++function wp_kses_bad_protocol_once2( $string, $allowed_protocols ) { + $string2 = wp_kses_decode_entities($string); + $string2 = preg_replace('/\s/', '', $string2); +@@ -926,6 +911,6 @@ + + $allowed = false; +- foreach ( (array) $_kses_allowed_protocols as $one_protocol) +- if (strtolower($one_protocol) == $string2) { ++ foreach ( (array) $allowed_protocols as $one_protocol ) ++ if ( strtolower($one_protocol) == $string2 ) { + $allowed = true; + break; diff --git a/wordpress.spec b/wordpress.spec index e3d1adf..6d98d00 100644 --- a/wordpress.spec +++ b/wordpress.spec @@ -3,13 +3,15 @@ URL: http://www.wordpress.org Name: wordpress Version: 2.8.6 Group: Applications/Publishing -Release: 3%{?dist} +Release: 4%{?dist} License: GPLv2 Source0: http://wordpress.org/%{name}-%{version}.tar.gz Source1: wordpress-httpd-conf Source2: README.fedora.wordpress Patch0: wordpress-2.8.6-r16625.patch Patch1: wordpress-debian_patches_hello.patch +Patch2: wordpress-2.8.6-r17172.patch + BuildRoot: %{_tmppath}/%{name}-%{version}-%{release}-root-%(%{__id_u} -n) Requires: php >= 4.1.0, webserver, php-mysql BuildArch: noarch @@ -23,6 +25,7 @@ almost trivial, to get information out to people on the web. %patch0 -p0 -b .16625 %patch1 -p1 -b .dolly +%patch2 -p1 -b .17172 # disable wp_version_check, updates are always installed via rpm sed -i -e "s,\(.*\)'wp_version_check'\(.*\),#\1'wp_version_check'\2,g" \ @@ -87,6 +90,9 @@ rm -rf ${RPM_BUILD_ROOT} %dir %{_sysconfdir}/wordpress %changelog +* Mon Jan 03 2011 Jon Ciesla - 2.8.6-4 +- Patch for security vulnerability, BZ 666782. + * Thu Dec 23 2010 Jon Ciesla - 2.8.6-3 - Change Requires from httpd to webserver, BZ 523480. - Patch for Hello Dolly lyrics, BZ 663966. From 8c600ef208f28a47c96b14eb1fd1f0b1d995b511 Mon Sep 17 00:00:00 2001 From: Jon Ciesla Date: Mon, 21 Mar 2011 09:25:14 -0500 Subject: [PATCH 05/21] Spec error. --- wordpress.spec | 9 --------- 1 file changed, 9 deletions(-) diff --git a/wordpress.spec b/wordpress.spec index 710c531..454a02f 100644 --- a/wordpress.spec +++ b/wordpress.spec @@ -99,15 +99,6 @@ rm -rf ${RPM_BUILD_ROOT} %{_datadir}/wordpress/wp-signup.php %changelog -<<<<<<< HEAD -* Mon Jan 03 2011 Jon Ciesla - 2.8.6-4 -- Patch for security vulnerability, BZ 666782. - -* Thu Dec 23 2010 Jon Ciesla - 2.8.6-3 -- Change Requires from httpd to webserver, BZ 523480. -- Patch for Hello Dolly lyrics, BZ 663966. -- Patch for security vulnerability, BZ 659319. - * Wed Feb 23 2011 Jon Ciesla - 3.1-1 - 3.1. From ea38f9f434aa527fbc56308ae161961d823e3395 Mon Sep 17 00:00:00 2001 From: Jon Ciesla Date: Mon, 21 Mar 2011 09:26:48 -0500 Subject: [PATCH 06/21] Spec error. --- wordpress.spec | 8 -------- 1 file changed, 8 deletions(-) diff --git a/wordpress.spec b/wordpress.spec index 454a02f..63a07cb 100644 --- a/wordpress.spec +++ b/wordpress.spec @@ -124,14 +124,6 @@ rm -rf ${RPM_BUILD_ROOT} * Mon Aug 09 2010 Jon Ciesla - 3.0.1-1 - 3.0.1. -* Mon Jan 03 2011 Jon Ciesla - 2.8.6-4 -- Patch for security vulnerability, BZ 666782. - -* Thu Dec 23 2010 Jon Ciesla - 2.8.6-3 -- Change Requires from httpd to webserver, BZ 523480. -- Patch for Hello Dolly lyrics, BZ 663966. -- Patch for security vulnerability, BZ 659319. - * Mon Jul 12 2010 Jon Ciesla - 2.8.6-3 - Remove bundled php-gettext and php-simplepie, - require and link to system versions, BZ 544720. From 7fff699c8934505aed8cad6e518f298b22aca3b6 Mon Sep 17 00:00:00 2001 From: =?UTF-8?q?Mat=C4=9Bj=20Cepl?= Date: Wed, 29 Jun 2011 21:30:31 +0200 Subject: [PATCH 07/21] New upstream release. --- wordpress.spec | 7 +++++-- 1 file changed, 5 insertions(+), 2 deletions(-) diff --git a/wordpress.spec b/wordpress.spec index 051c85e..9cf4af2 100644 --- a/wordpress.spec +++ b/wordpress.spec @@ -1,9 +1,9 @@ Summary: Blog tool and publishing platform URL: http://www.wordpress.org Name: wordpress -Version: 3.1.3 +Version: 3.1.4 Group: Applications/Publishing -Release: 3%{?dist} +Release: 1%{?dist} License: GPLv2 Source0: http://wordpress.org/%{name}-%{version}.tar.gz Source1: wordpress-httpd-conf @@ -107,6 +107,9 @@ rm -rf ${RPM_BUILD_ROOT} %dir %{_sysconfdir}/wordpress %changelog +* Wed Jun 29 2011 Matěj Cepl - 3.1.4-1 +- New upstream security release. + * Thu Jun 02 2011 Matěj Cepl - 3.1.3-3 - Actually, we just don't need gettext.php at all, it is provided by php itself. Just remove the file, don't make a symlink. From 73aa093c0ffe903c4a352c93a740e720128a4773 Mon Sep 17 00:00:00 2001 From: =?UTF-8?q?Mat=C4=9Bj=20Cepl?= Date: Wed, 29 Jun 2011 21:32:43 +0200 Subject: [PATCH 08/21] Actually don't forget to add new sources. --- .gitignore | 1 + sources | 2 +- 2 files changed, 2 insertions(+), 1 deletion(-) diff --git a/.gitignore b/.gitignore index 336fc17..d002ba8 100644 --- a/.gitignore +++ b/.gitignore @@ -6,3 +6,4 @@ wordpress-3.0.1.tar.gz /wordpress-3.1.1.tar.gz /wordpress-3.1.2.tar.gz /wordpress-3.1.3.tar.gz +/wordpress-3.1.4.tar.gz diff --git a/sources b/sources index ad6311b..7124a48 100644 --- a/sources +++ b/sources @@ -1 +1 @@ -dd0323f13f5b1c44636bb3db5ca1c717 wordpress-3.1.3.tar.gz +b6289783d88c965986a918e3d940e05e wordpress-3.1.4.tar.gz From 4214abd909392fade00537c3f4271d24cd06ae17 Mon Sep 17 00:00:00 2001 From: =?UTF-8?q?Mat=C4=9Bj=20Cepl?= Date: Wed, 29 Jun 2011 21:30:31 +0200 Subject: [PATCH 09/21] New upstream release. --- .gitignore | 1 + sources | 2 +- wordpress.spec | 7 +++++-- 3 files changed, 7 insertions(+), 3 deletions(-) diff --git a/.gitignore b/.gitignore index 336fc17..d002ba8 100644 --- a/.gitignore +++ b/.gitignore @@ -6,3 +6,4 @@ wordpress-3.0.1.tar.gz /wordpress-3.1.1.tar.gz /wordpress-3.1.2.tar.gz /wordpress-3.1.3.tar.gz +/wordpress-3.1.4.tar.gz diff --git a/sources b/sources index ad6311b..7124a48 100644 --- a/sources +++ b/sources @@ -1 +1 @@ -dd0323f13f5b1c44636bb3db5ca1c717 wordpress-3.1.3.tar.gz +b6289783d88c965986a918e3d940e05e wordpress-3.1.4.tar.gz diff --git a/wordpress.spec b/wordpress.spec index 051c85e..9cf4af2 100644 --- a/wordpress.spec +++ b/wordpress.spec @@ -1,9 +1,9 @@ Summary: Blog tool and publishing platform URL: http://www.wordpress.org Name: wordpress -Version: 3.1.3 +Version: 3.1.4 Group: Applications/Publishing -Release: 3%{?dist} +Release: 1%{?dist} License: GPLv2 Source0: http://wordpress.org/%{name}-%{version}.tar.gz Source1: wordpress-httpd-conf @@ -107,6 +107,9 @@ rm -rf ${RPM_BUILD_ROOT} %dir %{_sysconfdir}/wordpress %changelog +* Wed Jun 29 2011 Matěj Cepl - 3.1.4-1 +- New upstream security release. + * Thu Jun 02 2011 Matěj Cepl - 3.1.3-3 - Actually, we just don't need gettext.php at all, it is provided by php itself. Just remove the file, don't make a symlink. From 73abfe07eff4f833b0a96f72cdc431fe45f6c695 Mon Sep 17 00:00:00 2001 From: =?UTF-8?q?Mat=C4=9Bj=20Cepl?= Date: Wed, 13 Jul 2011 02:10:39 +0200 Subject: [PATCH 10/21] Remove FSF address patch --- wordpress-2.8.6-r16625.patch | 11 ----- wordpress-2.8.6-r17172.patch | 92 ------------------------------------ wordpress-FSF-address.patch | 12 ----- 3 files changed, 115 deletions(-) delete mode 100644 wordpress-2.8.6-r16625.patch delete mode 100644 wordpress-2.8.6-r17172.patch delete mode 100644 wordpress-FSF-address.patch diff --git a/wordpress-2.8.6-r16625.patch b/wordpress-2.8.6-r16625.patch deleted file mode 100644 index a373f85..0000000 --- a/wordpress-2.8.6-r16625.patch +++ /dev/null @@ -1,11 +0,0 @@ ---- wp-includes/comment.php~ 2009-07-21 18:10:34.000000000 -0500 -+++ wp-includes/comment.php 2010-12-23 08:55:05.433027996 -0600 -@@ -1365,7 +1365,7 @@ - trackback($tb_ping, $post_title, $excerpt, $post_id); - $pinged[] = $tb_ping; - } else { -- $wpdb->query( $wpdb->prepare("UPDATE $wpdb->posts SET to_ping = TRIM(REPLACE(to_ping, '$tb_ping', '')) WHERE ID = %d", $post_id) ); -+ $wpdb->query( $wpdb->prepare("UPDATE $wpdb->posts SET to_ping = TRIM(REPLACE(to_ping, %s, '')) WHERE ID = %d", $tb_ping, $post_id) ); - } - } - } diff --git a/wordpress-2.8.6-r17172.patch b/wordpress-2.8.6-r17172.patch deleted file mode 100644 index b78b7ae..0000000 --- a/wordpress-2.8.6-r17172.patch +++ /dev/null @@ -1,92 +0,0 @@ -diff -r -U2 wordpress.orig/wp-includes/formatting.php wordpress/wp-includes/formatting.php ---- wordpress.orig/wp-includes/formatting.php 2009-11-11 17:10:13.000000000 -0600 -+++ wordpress/wp-includes/formatting.php 2011-01-11 10:34:13.970920002 -0600 -@@ -2092,6 +2092,7 @@ - // Replace ampersands and single quotes only when displaying. - if ( 'display' == $context ) { -- $url = preg_replace('/&([^#])(?![a-z]{2,8};)/', '&$1', $url); -- $url = str_replace( "'", ''', $url ); -+ $url = wp_kses_normalize_entities( $url ); -+ $url = str_replace( '&', '&', $url ); -+ $url = str_replace( "'", ''', $url ); - } - -diff -r -U2 wordpress.orig/wp-includes/kses.php wordpress/wp-includes/kses.php ---- wordpress.orig/wp-includes/kses.php 2009-07-08 04:53:22.000000000 -0500 -+++ wordpress/wp-includes/kses.php 2011-01-11 10:47:04.468920001 -0600 -@@ -534,5 +534,5 @@ - } - -- if ( $arreach['name'] == 'style' ) { -+ if ( strtolower($arreach['name']) == 'style' ) { - $orig_value = $arreach['value']; - -@@ -626,5 +626,5 @@ - { - $thisval = $match[1]; -- if ( in_array($attrname, $uris) ) -+ if ( in_array(strtolower($attrname), $uris) ) - $thisval = wp_kses_bad_protocol($thisval, $allowed_protocols); - -@@ -642,5 +642,5 @@ - { - $thisval = $match[1]; -- if ( in_array($attrname, $uris) ) -+ if ( in_array(strtolower($attrname), $uris) ) - $thisval = wp_kses_bad_protocol($thisval, $allowed_protocols); - -@@ -658,5 +658,5 @@ - { - $thisval = $match[1]; -- if ( in_array($attrname, $uris) ) -+ if ( in_array(strtolower($attrname), $uris) ) - $thisval = wp_kses_bad_protocol($thisval, $allowed_protocols); - -@@ -882,12 +882,7 @@ - */ - function wp_kses_bad_protocol_once($string, $allowed_protocols) { -- global $_kses_allowed_protocols; -- $_kses_allowed_protocols = $allowed_protocols; -- -- $string2 = preg_split('/:|:|:/i', $string, 2); -- if ( isset($string2[1]) && !preg_match('%/\?%', $string2[0]) ) -- $string = wp_kses_bad_protocol_once2($string2[0]) . trim($string2[1]); -- else -- $string = preg_replace_callback('/^((&[^;]*;|[\sA-Za-z0-9])*)'.'(:|:|&#[Xx]3[Aa];)\s*/', 'wp_kses_bad_protocol_once2', $string); -+ $string2 = preg_split( '/:|�*58;|�*3a;/i', $string, 2 ); -+ if ( isset($string2[1]) && ! preg_match('%/\?%', $string2[0]) ) -+ $string = wp_kses_bad_protocol_once2( $string2[0], $allowed_protocols ) . trim( $string2[1] ); - - return $string; -@@ -903,19 +898,9 @@ - * @since 1.0.0 - * -- * @param mixed $matches string or preg_replace_callback() matches array to check for bad protocols -+ * @param string $string URI scheme to check against the whitelist -+ * @param string $allowed_protocols Allowed protocols - * @return string Sanitized content - */ --function wp_kses_bad_protocol_once2($matches) { -- global $_kses_allowed_protocols; -- -- if ( is_array($matches) ) { -- if ( ! isset($matches[1]) || empty($matches[1]) ) -- return ''; -- -- $string = $matches[1]; -- } else { -- $string = $matches; -- } -- -+function wp_kses_bad_protocol_once2( $string, $allowed_protocols ) { - $string2 = wp_kses_decode_entities($string); - $string2 = preg_replace('/\s/', '', $string2); -@@ -926,6 +911,6 @@ - - $allowed = false; -- foreach ( (array) $_kses_allowed_protocols as $one_protocol) -- if (strtolower($one_protocol) == $string2) { -+ foreach ( (array) $allowed_protocols as $one_protocol ) -+ if ( strtolower($one_protocol) == $string2 ) { - $allowed = true; - break; diff --git a/wordpress-FSF-address.patch b/wordpress-FSF-address.patch deleted file mode 100644 index 8992779..0000000 --- a/wordpress-FSF-address.patch +++ /dev/null @@ -1,12 +0,0 @@ -diff -up wordpress/wp-includes/kses.php.FSFaddr wordpress/wp-includes/kses.php ---- wordpress/wp-includes/kses.php.FSFaddr 2011-05-25 23:54:34.347025847 +0200 -+++ wordpress/wp-includes/kses.php 2011-05-25 23:56:18.403727954 +0200 -@@ -15,7 +15,7 @@ - * - * You should have received a copy of the GNU General Public License along - * with this program; if not, write to the Free Software Foundation, Inc., -- * 59 Temple Place, Suite 330, Boston, MA 02111-1307 USA or visit -+ * 51 Franklin St, Fifth Floor, Boston, MA 02110-1301, USA - * http://www.gnu.org/licenses/gpl.html - * - * [kses strips evil scripts!] From 7b9b4f88a1a9be2d47ff36bdd1eed51ee8afc6ce Mon Sep 17 00:00:00 2001 From: =?UTF-8?q?Mat=C4=9Bj=20Cepl?= Date: Mon, 23 Apr 2012 12:31:57 +0200 Subject: [PATCH 11/21] New upstream release (security release). --- .gitignore | 1 + sources | 2 +- wordpress.spec | 9 +++++++-- 3 files changed, 9 insertions(+), 3 deletions(-) diff --git a/.gitignore b/.gitignore index cb6ef41..1417aa9 100644 --- a/.gitignore +++ b/.gitignore @@ -17,3 +17,4 @@ wordpress-3.0.1.tar.gz /wordpress-3.3-RC2.tar.gz /wordpress-3.3.tar.gz /wordpress-3.3.1.tar.gz +/wordpress-3.3.2.tar.gz diff --git a/sources b/sources index fb3ad90..1ade4fb 100644 --- a/sources +++ b/sources @@ -1 +1 @@ -e94894be6e6d213175940ccc14e6c5e4 wordpress-3.3.1.tar.gz +bb38fa2bcde3b144e1a7fb096cd597a1 wordpress-3.3.2.tar.gz diff --git a/wordpress.spec b/wordpress.spec index a90049c..8ca7d21 100644 --- a/wordpress.spec +++ b/wordpress.spec @@ -4,7 +4,7 @@ Summary: Blog tool and publishing platform URL: http://www.wordpress.org Name: wordpress -Version: 3.3.1 +Version: 3.3.2 Group: Applications/Publishing Release: 1%{?dist} License: GPLv2 @@ -116,7 +116,12 @@ rm -rf ${RPM_BUILD_ROOT} %dir %{_sysconfdir}/wordpress %changelog -* Wed Jan 04 2012 'Matej Cepl ' - 3.3.1-1 +* Mon Apr 23 2012 'Matěj Cepl ' - 3.3.2-1 +- Security updates for uploading files. + (apparently no CVE exists yet; + http://seclists.org/oss-sec/2012/q2/164) + +* Wed Jan 04 2012 'Matěj Cepl ' - 3.3.1-1 - Security (XSS) and maintenance upstream release. * Tue Dec 13 2011 'Matěj Cepl ' - 3.3-1 From 2710f1675dd35a7f8e2795cf322b2ddf96ffc011 Mon Sep 17 00:00:00 2001 From: =?UTF-8?q?Mat=C4=9Bj=20Cepl?= Date: Mon, 23 Apr 2012 12:47:45 +0200 Subject: [PATCH 12/21] Fix changelog --- wordpress.spec | 10 ++++++---- 1 file changed, 6 insertions(+), 4 deletions(-) diff --git a/wordpress.spec b/wordpress.spec index 8ca7d21..63c51dd 100644 --- a/wordpress.spec +++ b/wordpress.spec @@ -6,7 +6,7 @@ URL: http://www.wordpress.org Name: wordpress Version: 3.3.2 Group: Applications/Publishing -Release: 1%{?dist} +Release: 2%{?dist} License: GPLv2 Source0: http://wordpress.org/%{name}-%{version}.tar.gz Source1: wordpress-httpd-conf @@ -116,10 +116,12 @@ rm -rf ${RPM_BUILD_ROOT} %dir %{_sysconfdir}/wordpress %changelog -* Mon Apr 23 2012 'Matěj Cepl ' - 3.3.2-1 +* Mon Apr 23 2012 'Matěj Cepl ' - 3.3.2-2 - Security updates for uploading files. - (apparently no CVE exists yet; - http://seclists.org/oss-sec/2012/q2/164) + * Fixed CVE-2011-0700: two XSS bug. Affects users of the Author + or Contributor role. + * Fixed CVE-2011-0701: potential information disclosure of + posts through the media uploader. * Wed Jan 04 2012 'Matěj Cepl ' - 3.3.1-1 - Security (XSS) and maintenance upstream release. From ef7ca4bf10b38ec327636cef1a90643b3b195955 Mon Sep 17 00:00:00 2001 From: =?UTF-8?q?Mat=C4=9Bj=20Cepl?= Date: Wed, 13 Jun 2012 22:50:30 +0200 Subject: [PATCH 13/21] New upstream release Conflicts: .gitignore sources wordpress.spec --- .gitignore | 1 + sources | 2 +- wordpress.spec | 15 +++++++++++---- 3 files changed, 13 insertions(+), 5 deletions(-) diff --git a/.gitignore b/.gitignore index b9ac54c..59fb246 100644 --- a/.gitignore +++ b/.gitignore @@ -17,3 +17,4 @@ wordpress-3.0.1.tar.gz /wordpress-3.3.tar.gz /wordpress-3.3.1.tar.gz /wordpress-3.3.2.tar.gz +/wordpress-3.4.tar.gz diff --git a/sources b/sources index 1ade4fb..22cfaf4 100644 --- a/sources +++ b/sources @@ -1 +1 @@ -bb38fa2bcde3b144e1a7fb096cd597a1 wordpress-3.3.2.tar.gz +e080b6761c61c0f0f2b75d2bb5a7d0c9 wordpress-3.4.tar.gz diff --git a/wordpress.spec b/wordpress.spec index 57f89e5..db2ba64 100644 --- a/wordpress.spec +++ b/wordpress.spec @@ -1,14 +1,15 @@ %global wp_content %{_datadir}/wordpress/wp-content -%global betatag RC2 +#%#global betatag -RC3 Summary: Blog tool and publishing platform URL: http://www.wordpress.org Name: wordpress -Version: 3.3.2 +Version: 3.4 Group: Applications/Publishing -Release: 2%{?dist} +#Release: 0.2.%{betatag}%{?dist} +Release: 1%{?dist} License: GPLv2 -Source0: http://wordpress.org/%{name}-%{version}.tar.gz +Source0: http://wordpress.org/%{name}-%{version}%{?betatag}.tar.gz Source1: wordpress-httpd-conf Source2: README.fedora.wordpress Source3: README.fedora.wordpress-mu @@ -116,6 +117,12 @@ rm -rf ${RPM_BUILD_ROOT} %dir %{_sysconfdir}/wordpress %changelog +* Wed Jun 13 2012 Matej Cepl - 3.4-1 +- New upstream release. The main changes from the upstream + release notes: + * theme customizer + * XML-RPC themes and API improvements + * Mon Apr 23 2012 'Matěj Cepl ' - 3.3.2-2 - Security updates for uploading files. * Fixed CVE-2011-0700: two XSS bug. Affects users of the Author From c3a27fde68d3f7969f9a8330d8573149cb0238ae Mon Sep 17 00:00:00 2001 From: =?UTF-8?q?Mat=C4=9Bj=20Cepl?= Date: Thu, 28 Jun 2012 20:42:38 +0200 Subject: [PATCH 14/21] New upstream release (minor & security changes) --- .gitignore | 1 + sources | 2 +- wordpress.spec | 5 ++++- 3 files changed, 6 insertions(+), 2 deletions(-) diff --git a/.gitignore b/.gitignore index 59fb246..85bfeda 100644 --- a/.gitignore +++ b/.gitignore @@ -18,3 +18,4 @@ wordpress-3.0.1.tar.gz /wordpress-3.3.1.tar.gz /wordpress-3.3.2.tar.gz /wordpress-3.4.tar.gz +/wordpress-3.4.1.tar.gz diff --git a/sources b/sources index 22cfaf4..ffdae5b 100644 --- a/sources +++ b/sources @@ -1 +1 @@ -e080b6761c61c0f0f2b75d2bb5a7d0c9 wordpress-3.4.tar.gz +5f6c1dcbe0b8031235f107b7479d30a5 wordpress-3.4.1.tar.gz diff --git a/wordpress.spec b/wordpress.spec index db2ba64..d1b7399 100644 --- a/wordpress.spec +++ b/wordpress.spec @@ -4,7 +4,7 @@ Summary: Blog tool and publishing platform URL: http://www.wordpress.org Name: wordpress -Version: 3.4 +Version: 3.4.1 Group: Applications/Publishing #Release: 0.2.%{betatag}%{?dist} Release: 1%{?dist} @@ -117,6 +117,9 @@ rm -rf ${RPM_BUILD_ROOT} %dir %{_sysconfdir}/wordpress %changelog +* Thu Jun 28 2012 Matej Cepl - 3.4.1-1 +- New upstream release. Just improvements and security issues. + * Wed Jun 13 2012 Matej Cepl - 3.4-1 - New upstream release. The main changes from the upstream release notes: From 5faa94e8f3ed4362d2248f5a357bd16ba6cb4bd0 Mon Sep 17 00:00:00 2001 From: =?UTF-8?q?Mat=C4=9Bj=20Cepl?= Date: Sun, 16 Sep 2012 17:12:56 +0200 Subject: [PATCH 15/21] New upstream release. Also: * use system PHPMailer * requires needed php extensions --- .gitignore | 30 +------------------------ sources | 2 +- wordpress.spec | 61 ++++++++++++++++++++++++++++++++++++++++++-------- 3 files changed, 54 insertions(+), 39 deletions(-) diff --git a/.gitignore b/.gitignore index f4e7ed0..4f114c6 100644 --- a/.gitignore +++ b/.gitignore @@ -1,29 +1 @@ -wordpress-3.0.1.tar.gz -/wordpress-3.0.2.tar.gz -/wordpress-3.0.3.tar.gz -/wordpress-3.0.4.tar.gz -/wordpress-3.1.tar.gz -/wordpress-3.1.1.tar.gz -/wordpress-3.1.2.tar.gz -/wordpress-3.1.3.tar.gz -/wordpress-3.2-RC1.zip -/wordpress-3.2-RC3.zip -/wordpress-3.2.tar.gz -/wordpress-3.2.1.tar.gz -/wordpress-3.3-beta2.tar.gz -/wordpress-3.3-beta3.tar.gz -/wordpress-3.3-beta4.tar.gz -/wordpress-3.3-RC1.tar.gz -/wordpress-3.3-RC2.tar.gz -/wordpress-3.3.tar.gz -/wordpress-3.3.1.tar.gz -/wordpress-3.4-beta1.tar.gz -/wordpress-3.4-beta2.tar.gz -/wordpress-3.4-beta3.tar.gz -/wordpress-3.4-beta4.tar.gz -/wordpress-3.4-RC1.tar.gz -/wordpress-3.4-RC2.tar.gz -/wordpress-3.4-RC3.tar.gz -/wordpress-3.4.tar.gz -/wordpress-3.4.1.tar.gz -/wordpress-3.4.2.tar.gz +/wordpress-3.5.tar.gz diff --git a/sources b/sources index 4697198..3744939 100644 --- a/sources +++ b/sources @@ -1 +1 @@ -dfc56cee27eec8fb79070f033ecd4b25 wordpress-3.4.2.tar.gz +105b5baff67344528bb5d8b71c050b0d wordpress-3.5.tar.gz diff --git a/wordpress.spec b/wordpress.spec index 414d616..c17dc8c 100644 --- a/wordpress.spec +++ b/wordpress.spec @@ -1,15 +1,16 @@ %global wp_content %{_datadir}/wordpress/wp-content -#%#global betatag -RC3 +%global betatag RC3 Summary: Blog tool and publishing platform URL: http://www.wordpress.org Name: wordpress -Version: 3.4.2 +Version: 3.5 Group: Applications/Publishing -#Release: 0.2.%{betatag}%{?dist} -Release: 2%{?dist} +#Release: 0.5.%{betatag}%{?dist} +Release: 1%{?dist} License: GPLv2 -Source0: http://wordpress.org/%{name}-%{version}%{?betatag}.tar.gz +#Source0: http://wordpress.org/%{name}-%{version}-%{betatag}.tar.gz +Source0: http://wordpress.org/%{name}-%{version}.tar.gz Source1: wordpress-httpd-conf Source2: README.fedora.wordpress Source3: README.fedora.wordpress-mu @@ -19,7 +20,41 @@ Patch0: wordpress-debian_patches_hello.patch # Move wp-content to /var/www/wordpress/ Patch1: wordpress-move-wp-content.patch BuildRoot: %{_tmppath}/%{name}-%{version}-%{release}-root-%(%{__id_u} -n) -Requires: php >= 5.2.4, webserver, php-mysql, php-gettext, php-simplepie +%if 0%{?rhel} == 5 +Requires: php53 >= 5.2.4, php53-simplepie +%else +Requires: php >= 5.2.4, php-simplepie +%endif +# Required php extension (detected by phpci) +Requires: php-curl +Requires: php-date +Requires: php-dom +Requires: php-enchant +# not yet available for RHEL Requires: php-ereg +Requires: php-exif +Requires: php-fileinfo +# not yet available for RHEL Requires: php-filter +Requires: php-gettext +Requires: php-hash +Requires: php-iconv +Requires: php-json +Requires: php-libxml +Requires: php-mbstring +Requires: php-mysql +Requires: php-openssl +Requires: php-pcre +Requires: php-pdo +Requires: php-posix +Requires: php-reflection +Requires: php-simplexml +Requires: php-sockets +Requires: php-spl +Requires: php-tokenizer +Requires: php-zip +Requires: php-zlib +# Unbundled libraries +Requires: php-PHPMailer +Requires: webserver Provides: wordpress-mu = %{version}-%{release} Obsoletes: wordpress-mu < 2.9.3 BuildArch: noarch @@ -65,13 +100,14 @@ find ${RPM_BUILD_ROOT} -type f -empty -exec rm -vf {} \; # These are docs, remove them from here, docify them later rm -f ${RPM_BUILD_ROOT}%{_datadir}/wordpress/{license.txt,readme.html} -# Remove bundled php-gettext and link to system copy -rm -f ${RPM_BUILD_ROOT}%{_datadir}/wordpress/wp-includes/gettext.php - # Remove bundled php-simplepie and link to system copy rm -f ${RPM_BUILD_ROOT}%{_datadir}/wordpress/wp-includes/class-simplepie.php ln -sf /usr/share/php/php-simplepie/simplepie.inc ${RPM_BUILD_ROOT}%{_datadir}/wordpress/wp-includes/class-simplepie.php +# Remove bundled PHPMailer and link to system one +rm -f ${RPM_BUILD_ROOT}%{_datadir}/wordpress/wp-includes/class-{phpmailer,smtp,pop3}.php +ln -sf /usr/share/php/PHPMailer/*php ${RPM_BUILD_ROOT}%{_datadir}/wordpress/wp-includes/ + # Remove backup copies of patches find ${RPM_BUILD_ROOT} \( -name \*.dolly -o -name \*.rhbz522897 -o -name \*.FSFaddr \) \ -print -delete @@ -117,6 +153,13 @@ rm -rf ${RPM_BUILD_ROOT} %dir %{_sysconfdir}/wordpress %changelog +* Wed Dec 12 2012 Matěj Cepl - 3.5-1 +- New upstream release. + +* Mon Oct 29 2012 Remi Collet - 3.5-0.3.beta2 +- use system PHPMailer +- requires needed php extensions + * Thu Sep 06 2012 Matej Cepl - 3.4.2-2 - Upstream security update. From 4c005057881d2be23fff27817c604ccfea735f17 Mon Sep 17 00:00:00 2001 From: =?UTF-8?q?Mat=C4=9Bj=20Cepl?= Date: Wed, 12 Dec 2012 14:11:14 +0100 Subject: [PATCH 16/21] Add a comment explainin patch1 non-inclusion. --- wordpress.spec | 1 + 1 file changed, 1 insertion(+) diff --git a/wordpress.spec b/wordpress.spec index c17dc8c..5750940 100644 --- a/wordpress.spec +++ b/wordpress.spec @@ -18,6 +18,7 @@ Source3: README.fedora.wordpress-mu # (and replace it with Free Software Song) Patch0: wordpress-debian_patches_hello.patch # Move wp-content to /var/www/wordpress/ +# This patch doesn’t work well, see bugzilla.redhat.com/522897 Patch1: wordpress-move-wp-content.patch BuildRoot: %{_tmppath}/%{name}-%{version}-%{release}-root-%(%{__id_u} -n) %if 0%{?rhel} == 5 From fd22341ed579c4b52d7c2009f4ab2afce493265b Mon Sep 17 00:00:00 2001 From: Remi Collet Date: Wed, 30 Jan 2013 14:20:59 +0100 Subject: [PATCH 17/21] fix merge issue --- wordpress.spec | 4 ---- 1 file changed, 4 deletions(-) diff --git a/wordpress.spec b/wordpress.spec index 2bb2785..2a511ac 100644 --- a/wordpress.spec +++ b/wordpress.spec @@ -119,10 +119,6 @@ for fic in phpmailer smtp pop3; do ${RPM_BUILD_ROOT}%{_datadir}/wordpress/wp-includes/class-$fic.php done -# Remove bundled PHPMailer and link to system one -rm -f ${RPM_BUILD_ROOT}%{_datadir}/wordpress/wp-includes/class-{phpmailer,smtp,pop3}.php -ln -sf /usr/share/php/PHPMailer/*php ${RPM_BUILD_ROOT}%{_datadir}/wordpress/wp-includes/ - # Remove backup copies of patches find ${RPM_BUILD_ROOT} \( -name \*.dolly -o -name \*.rhbz522897 -o -name \*.FSFaddr \) \ -print -delete From 5b4d9f141e3eadd1d84b0d0f97ffada865a4f650 Mon Sep 17 00:00:00 2001 From: Remi Collet Date: Tue, 12 Feb 2013 12:15:36 +0100 Subject: [PATCH 18/21] provides POP3 class #905867 --- wordpress.spec | 17 ++++++++++++++--- 1 file changed, 14 insertions(+), 3 deletions(-) diff --git a/wordpress.spec b/wordpress.spec index 2a511ac..e2f7284 100644 --- a/wordpress.spec +++ b/wordpress.spec @@ -7,7 +7,7 @@ Name: wordpress Version: 3.5.1 Group: Applications/Publishing #Release: 0.5.%{betatag}%{?dist} -Release: 1%{?dist} +Release: 2%{?dist} License: GPLv2 #Source0: http://wordpress.org/%{name}-%{version}-%{betatag}.tar.gz Source0: http://wordpress.org/%{name}-%{version}.tar.gz @@ -24,7 +24,8 @@ BuildRoot: %{_tmppath}/%{name}-%{version}-%{release}-root-%(%{__id_u} -n) BuildArch: noarch %if 0%{?rhel} == 5 -Requires: php53 >= 5.2.4, php53-simplepie +Requires: php53 >= 5.2.4 +Requires: php53-simplepie >= 1.3.1 %else Requires: php >= 5.2.4 Requires: php-simplepie >= 1.3.1 @@ -109,11 +110,16 @@ rm -f ${RPM_BUILD_ROOT}%{_datadir}/wordpress/{license.txt,readme.html} # Remove bundled php-simplepie and link to system copy rm ${RPM_BUILD_ROOT}%{_datadir}/wordpress/wp-includes/class-simplepie.php rm -rf ${RPM_BUILD_ROOT}%{_datadir}/wordpress/wp-includes/SimplePie +%if 0%{?rhel} == 5 +ln -sf /usr/share/php/php53-simplepie/autoloader.php \ +%else ln -sf /usr/share/php/php-simplepie/autoloader.php \ +%endif ${RPM_BUILD_ROOT}%{_datadir}/wordpress/wp-includes/class-simplepie.php # Remove bundled PHPMailer and link to system one -for fic in phpmailer smtp pop3; do +# Note POP3 is not from PHPMailer but from SquirrelMail +for fic in phpmailer smtp; do rm ${RPM_BUILD_ROOT}%{_datadir}/wordpress/wp-includes/class-$fic.php ln -sf /usr/share/php/PHPMailer/class.$fic.php \ ${RPM_BUILD_ROOT}%{_datadir}/wordpress/wp-includes/class-$fic.php @@ -164,6 +170,11 @@ rm -rf ${RPM_BUILD_ROOT} %dir %{_sysconfdir}/wordpress %changelog +* Tue Feb 12 2013 Remi Collet - 3.5.1-2 +- provides POP3 class #905867 + POP3 is not from PHPMailer, but from SquirrelMail +- fix simplepie links (for all branches) + * Wed Jan 30 2013 Remi Collet - 3.5.1-1 - version 3.5.1, various bug and security fixes: CVE-2013-0235, CVE-2013-0236 and CVE-2013-0237 From 5b4f3ee2593ca594954e67c44e457e2de84857eb Mon Sep 17 00:00:00 2001 From: Remi Collet Date: Mon, 24 Jun 2013 09:17:35 +0200 Subject: [PATCH 19/21] version 3.5.1, various bug and security fixes: CVE-2013-2173 CVE-2013-2199 CVE-2013-2200 CVE-2013-2201 CVE-2013-2202 CVE-2013-2203 CVE-2013-2204 --- .gitignore | 3 +++ sources | 2 +- wordpress.spec | 11 ++++++++--- 3 files changed, 12 insertions(+), 4 deletions(-) diff --git a/.gitignore b/.gitignore index a3311bf..0569754 100644 --- a/.gitignore +++ b/.gitignore @@ -1,3 +1,5 @@ +*spec +clog wordpress-3.0.1.tar.gz /wordpress-3.0.2.tar.gz /wordpress-3.0.3.tar.gz @@ -35,3 +37,4 @@ wordpress-3.0.1.tar.gz /wordpress-3.5-RC3.tar.gz /wordpress-3.5.tar.gz /wordpress-3.5.1.tar.gz +/wordpress-3.5.2.tar.gz diff --git a/sources b/sources index 301c035..60120d9 100644 --- a/sources +++ b/sources @@ -1 +1 @@ -409889c98b13cbdbb9fd121df859ae3e wordpress-3.5.1.tar.gz +90acae65199db7b33084ef36860d7f22 wordpress-3.5.2.tar.gz diff --git a/wordpress.spec b/wordpress.spec index e2f7284..f79f5d1 100644 --- a/wordpress.spec +++ b/wordpress.spec @@ -4,10 +4,10 @@ Summary: Blog tool and publishing platform URL: http://www.wordpress.org Name: wordpress -Version: 3.5.1 +Version: 3.5.2 Group: Applications/Publishing #Release: 0.5.%{betatag}%{?dist} -Release: 2%{?dist} +Release: 1%{?dist} License: GPLv2 #Source0: http://wordpress.org/%{name}-%{version}-%{betatag}.tar.gz Source0: http://wordpress.org/%{name}-%{version}.tar.gz @@ -170,6 +170,11 @@ rm -rf ${RPM_BUILD_ROOT} %dir %{_sysconfdir}/wordpress %changelog +* Mon Jun 24 2013 Remi Collet - 3.5.2-1 +- version 3.5.1, various bug and security fixes: + CVE-2013-2173 CVE-2013-2199 CVE-2013-2200 CVE-2013-2201 + CVE-2013-2202 CVE-2013-2203 CVE-2013-2204 + * Tue Feb 12 2013 Remi Collet - 3.5.1-2 - provides POP3 class #905867 POP3 is not from PHPMailer, but from SquirrelMail @@ -182,7 +187,7 @@ rm -rf ${RPM_BUILD_ROOT} upstream archive content change - protect akismet content (from upstream .htaccess) -* Mon Jan 2 2013 Remi Collet - 3.5-3 +* Wed Jan 2 2013 Remi Collet - 3.5-3 - fix links to system PHPMailer library * Sun Dec 16 2012 Remi Collet - 3.5-2 From dbcbfdff5bd9259f42b60d8c352b5303949ade3f Mon Sep 17 00:00:00 2001 From: Remi Collet Date: Mon, 24 Jun 2013 09:24:31 +0200 Subject: [PATCH 20/21] fix ignore list --- .gitignore | 2 +- 1 file changed, 1 insertion(+), 1 deletion(-) diff --git a/.gitignore b/.gitignore index 0569754..0848b5c 100644 --- a/.gitignore +++ b/.gitignore @@ -1,4 +1,4 @@ -*spec +*spec~ clog wordpress-3.0.1.tar.gz /wordpress-3.0.2.tar.gz From b4a77246a78ef1f245131b54a587cdb69a2de2cc Mon Sep 17 00:00:00 2001 From: Remi Collet Date: Mon, 24 Jun 2013 09:26:49 +0200 Subject: [PATCH 21/21] monday's typo --- wordpress.spec | 2 +- 1 file changed, 1 insertion(+), 1 deletion(-) diff --git a/wordpress.spec b/wordpress.spec index f79f5d1..570611a 100644 --- a/wordpress.spec +++ b/wordpress.spec @@ -171,7 +171,7 @@ rm -rf ${RPM_BUILD_ROOT} %changelog * Mon Jun 24 2013 Remi Collet - 3.5.2-1 -- version 3.5.1, various bug and security fixes: +- version 3.5.2, various bug and security fixes: CVE-2013-2173 CVE-2013-2199 CVE-2013-2200 CVE-2013-2201 CVE-2013-2202 CVE-2013-2203 CVE-2013-2204