Package: wordpress / 4.1+dfsg-1+deb8u17
Metadata
Package | Version | Patches format |
---|---|---|
wordpress | 4.1+dfsg-1+deb8u17 | 3.0 (quilt) |
Patch series
view the series filePatch | File delta | Description |
---|---|---|
ca certificate | (download) |
wp-includes/class-http.php |
2 1 + 1 - 0 ! |
use system ca file Instead of the shipped CA file use the system one found in the Debian ca-certificates package. Bug-Debian: http://bugs.debian.org/748965 |
001readme.patch | (download) |
readme.html |
2 1 + 1 - 0 ! |
fixing readme file |
003installer.patch | (download) |
wp-admin/install.php |
5 5 + 0 - 0 ! |
patching install.php to permit a valid upload path |
010disabling_update_note.patch | (download) |
wp-admin/includes/update.php |
2 2 + 0 - 0 ! |
disabled the the "please update" warning, thanks to hans spaans and rolf leggewie (closes: #506685) |
mu.patch | (download) |
wp-admin/network.php |
8 4 + 4 - 0 ! |
--- |
cs32163_query_sanity_checks | (download) |
wp-includes/wp-db.php |
788 739 + 49 - 0 ! |
--- |
cs32165_sanitize_orderby | (download) |
wp-includes/formatting.php |
22 12 + 10 - 0 ! |
--- |
cs32172_filename_check | (download) |
wp-includes/functions.php |
2 1 + 1 - 0 ! |
--- |
cs32174_multisite_switch | (download) |
wp-includes/capabilities.php |
12 8 + 4 - 0 ! |
--- |
cs32176_dashboard_esc_titles | (download) |
wp-admin/includes/class-wp-comments-list-table.php |
4 2 + 2 - 0 ! |
--- |
cs32234_wpdb_query_sanity | (download) |
wp-includes/wp-db.php |
21 20 + 1 - 0 ! |
--- |
cs32307_dbstring_length | (download) |
wp-includes/wp-db.php |
114 114 + 0 - 0 ! |
sanity check strings too long XSS bug if you send >64kB long comments |
cs32387_mysql_char_encode | (download) |
wp-admin/includes/upgrade.php |
53 53 + 0 - 0 ! |
cve-2015-8834 xss via comment WPDB: When checking that a string can be sent to MySQL, we shouldn't use |
cs32393_rm_genericons_example | (download) |
wp-content/themes/twentyfifteen/genericons/example.html |
719 0 + 719 - 0 ! |
remove genericons example files These example files had a XSS and are not used |
cs33357_autodraft_perms | (download) |
wp-admin/includes/dashboard.php |
4 4 + 0 - 0 ! |
cve-2015-5623 check perms on auto-draft Capabilities: When creating an auto-draft, ensure that the current user still has permission to do so. |
cs33359_reliable_shortcode | (download) |
wp-includes/class-wp-embed.php |
6 5 + 1 - 0 ! |
cve-2015-5622 improve reliability of shortcodes There are no shortcode input escaping functions available in core even though the Shortcode API is increasingly strict about not allowing special characters inside shortcode attributes. |
cs33555_ids_are_integers | (download) |
wp-includes/post.php |
7 4 + 3 - 0 ! |
ids are integers Remove source of SQL Injection CVE-2015-2213 |
cs33535_hash_equals_widgets | (download) |
wp-includes/class-wp-customize-widgets.php |
2 1 + 1 - 0 ! |
use hash_equals() for widgets Fixes a potiential timing side-channel attack CVE-2015-5730 |
cs33542_post_lock_release | (download) |
wp-admin/includes/post.php |
2 1 + 1 - 0 ! |
heartbeat: ensure post locks are released. Prevent an attacker from locking a post from being edited CVE-2015-5731 |
cs33529_xss_widget_title | (download) |
wp-includes/default-widgets.php |
2 1 + 1 - 0 ! |
nav menus: consistent titles in widgets Prevent XSS attack in widget titles CVE-2015-5732 |
cs_33549_xss_theme_view | (download) |
wp-includes/theme.php |
25 2 + 23 - 0 ! |
themes: fix some broken links in the legacy theme preview CVE-2015-5734 |
cs34137_escape_email | (download) |
wp-admin/includes/class-wp-ms-users-list-table.php |
2 1 + 1 - 0 ! |
escape email addresses |
cs34144_shortcode_close_elements | (download) |
wp-includes/media.php |
2 2 + 0 - 0 ! |
don't allow unclosed html elements in attributes CVE-2015-5714 |
cs34151_unsticky_private_posts | (download) |
wp-includes/class-wp-xmlrpc-server.php |
4 2 + 2 - 0 ! |
xmlrpc: don't allow private posts to be sticky. CVE-2015-5715 |
cs36185_xss_theme | (download) |
wp-includes/class-wp-theme.php |
8 4 + 4 - 0 ! |
stop xss in theme title Backport of changeset 36185 Fixes CVE-2016-1564 |
cs36435_http_valid_ip | (download) |
wp-includes/http.php |
2 1 + 1 - 0 ! |
http: 0.1.2.3 is not valid ip Check for IP address starting with 0. |
cs36444_plug_valid_redirect | (download) |
wp-includes/pluggable.php |
12 10 + 2 - 0 ! |
better validation of the url used in http redirects. |
cs37762_admin_auth_redirect | (download) |
wp-includes/pluggable.php |
20 8 + 12 - 0 ! |
admin: allow for the consistent filtering of auth_redirect_scheme |
cs37773_customize_preview_urls | (download) |
wp-admin/customize.php |
2 2 + 0 - 0 ! |
customize: make sure that preview and return urls are urls. |
cs37781_taxonomy_cap_check_save | (download) |
wp-admin/includes/post.php |
7 7 + 0 - 0 ! |
taxonomy: more specific cap check when processing category data on post save. |
cs37790_admin_escape_attach | (download) |
wp-includes/post-template.php |
2 1 + 1 - 0 ! |
admin: escape attachment name in case it contains special characters |
cs37800_cap_edit_post | (download) |
wp-admin/includes/ajax-actions.php |
2 1 + 1 - 0 ! |
revisions: change the capability needed to view revision diffs to edit_post. |
cs37815_escape_url_permalinks | (download) |
wp-admin/includes/post.php |
10 5 + 5 - 0 ! |
admin: escape url-encoded permalinks |
cs37818_media_extensionless_filenames | (download) |
wp-includes/formatting.php |
11 10 + 1 - 0 ! |
media: improve handling of extensionless filenames. |
cs38538_sanitize_media_filename | (download) |
wp-admin/includes/media.php |
2 1 + 1 - 0 ! |
sanitize title of uploaded filename Convert uploaded filename to title, but sanitize it Fixes CVE-2016-7168 |
cs38524_uploader_upgrader | (download) |
wp-admin/includes/class-wp-upgrader.php |
6 5 + 1 - 0 ! |
upgrade/install: sanitize file name in file_upload_upgrader |
CVE 2016 4029.patch | (download) |
wp-includes/http.php |
2 1 + 1 - 0 ! |
cve-2016-4029 WordPress before 4.5 does not consider octal and hexadecimal IP address formats when determining an intranet address, which allows remote attackers to bypass an intended SSRF protection mechanism via a crafted address. https://codex.wordpress.org/Version_4.5 See also https://wpvulndb.com/vulnerabilities/8473 |
CVE 2016 6634.patch | (download) |
wp-admin/network/settings.php |
2 1 + 1 - 0 ! |
cve-2016-6634 Cross-site scripting (XSS) vulnerability in the network settings page in WordPress before 4.5 allows remote attackers to inject arbitrary web script or HTML via unspecified vectors. https://wpvulndb.com/vulnerabilities/8474 |
CVE 2016 6635.patch | (download) |
wp-admin/includes/ajax-actions.php |
2 2 + 0 - 0 ! |
cve-2016-6635 Cross-site request forgery (CSRF) vulnerability in the wp_ajax_wp_compression_test function in wp-admin/includes/ajax-actions.php in WordPress before 4.5 allows remote attackers to hijack the authentication of administrators for requests that change the script compression option. Function wp_json_encode did not exist in 3.6.1. This required a backport of related functions. |
cs39795_wprand_multisite_key | (download) |
wp-includes/ms-functions.php |
4 2 + 2 - 0 ! |
multisite: use `wp_rand()` in signup key creation. |
cs39760_nonce_widget | (download) |
wp-admin/includes/screen.php |
3 2 + 1 - 0 ! |
add nonce for widget accessibility mode. |
cs39772_example_mail | (download) |
wp-mail.php |
6 6 + 0 - 0 ! |
mail: disable wp-mail.php when `mailserver_url` is mail.example.com. |
cs39807_theme_name_fallback | (download) |
wp-includes/class-wp-theme.php |
5 3 + 2 - 0 ! |
themes: fix markup for theme name fallbacks. |
cs39808_translate_plugin_update | (download) |
wp-admin/update-core.php |
1 1 + 0 - 0 ! |
updates: translate plugin data on the updates screen. |
cs39728_39790_phpmailer_5.2.22 | (download) |
wp-includes/class-phpmailer.php |
2251 1513 + 738 - 0 ! |
upgrade phpmailer to 5.2.22 Fixes some RCE vulnerabilities CVE-2016-10033 and CVE-2016-10045 Needed changeset 39728 and 39790 |
cs39838_image_type_check | (download) |
wp-includes/functions.php |
61 53 + 8 - 0 ! |
media: improve image filetype checking This adds a new function wp_get_image_mime() which is used by wp_check_filetype_and_ext() to validate image files using exif_imagetype() if available instead of getimagesize(). getimagesize() is less performant than exif_imagetype() and is dependent on GD. If exif_imagetype() is not available, it falls back to getimagesize() as before. If wp_check_filetype_and_ext() can't validate the filetype, we now return false for ext/MIME values. Includes the small fix in changeset 39857 too |
cs39976_press_this | (download) |
wp-admin/press-this.php |
143 83 + 60 - 0 ! |
fix permission problem in press this Press This: Do not show Categories & Tags UI for users who cannot assign terms to posts anyways. |
cs39962_sqli_special_names | (download) |
wp-includes/query.php |
11 6 + 5 - 0 ! |
query: remove sqli with special chars Query: Ensure that queries work correctly with post type names with special characters. Merge of [39952] to the 4.1 branch. |
cs39985_excerpt_table | (download) |
wp-admin/includes/class-wp-posts-list-table.php |
5 3 + 2 - 0 ! |
cross-site scripting (xss) in posts list table Posts, Post Types: When using Excerpt mode on the Posts list table, ensure the excerpt output matches what was manually entered into the Excerpt field. Merges changeset 39956 to the 4.1 branch. |
cs40155_media_metadata | (download) |
wp-admin/includes/media.php |
4 4 + 0 - 0 ! |
validate video and audio metadata |
cs40190_redirect | (download) |
wp-includes/pluggable.php |
2 1 + 1 - 0 ! |
strip control characters before validating redirect |
cs40167_youtube_id | (download) |
wp-includes/media.php |
2 1 + 1 - 0 ! |
embeds: url encode youtube video ids for broader compatibility |
cs40176_plugin_delete | (download) |
wp-admin/plugins.php |
8 8 + 0 - 0 ! |
plugin: add file check to plugin deletions |
cs40699_post_meta_checks | (download) |
wp-includes/class-wp-xmlrpc-server.php |
5 5 + 0 - 0 ! |
adjust post meta checks Fixes CVE-2017-962 Improper handling of post meta data values in the XML-RPC API. |
cs40684_whilelist_post_args_xmlrpc | (download) |
wp-includes/class-wp-xmlrpc-server.php |
30 24 + 6 - 0 ! |
whitelist post arguments in xml-rpc Fixes CVE-2017-9065 - Lack of capability checks for post meta data in the XML-RPC API. |
cs40730_nonce_filesystem_creds | (download) |
wp-admin/includes/file.php |
37 27 + 10 - 0 ! |
add nonce for updating file system credentials. Fixes CVE-2017-9064 - A Cross Site Request Forgery (CRSF) vulnerability was discovered in the filesystem credentials dialog. |
cs40743_media_simply_upload_error | (download) |
wp-includes/js/plupload/handlers.js |
23 16 + 7 - 0 ! |
media: simplify upload error message construction. Fixes CVE-2017-9061 XSS when attempting to upload very large files |
cs40711_invalid_customization | (download) |
wp-admin/customize.php |
2 1 + 1 - 0 ! |
customize: ignore invalid customization sessions. Fixes CVE-2017-9063 - A cross-site scripting (XSS) vulnerability was discovered related to the Customizer. |
CVE 2017 8295 | (download) |
wp-includes/pluggable.php |
9 3 + 6 - 0 ! |
don't use server_name for emails WordPress uses the SERVER_NAME variable to generate the from address for password resets. This variable can be set by the hostname sent by the client, which means it can be spoofed. This patch fixes CVE-2017-8295 |