-----BEGIN PGP SIGNED MESSAGE----- Hash: SHA512 Format: 1.8 Date: Sun, 30 Jun 2024 19:28:36 +1000 Source: wordpress Architecture: source Version: 6.5.5+dfsg1-1 Distribution: unstable Urgency: medium Maintainer: Craig Small <csmall@debian.org> Changed-By: Craig Small <csmall@debian.org> Closes: 1074486 Changes: wordpress (6.5.5+dfsg1-1) unstable; urgency=medium . * New upstream security release Closes: #1074486 Fixes the following CVEs - Stored XSS via HTMP API CVE-2024-6307 - Stored XSS in Template Part block CVE-2024-31111 - Relative Path traversal CVE-2024-32111 Checksums-Sha1: b29ae1712e1565c580b965e1644b071ba30d1cf2 2420 wordpress_6.5.5+dfsg1-1.dsc 287e7fe783a32061ca43c598b1ad54d2e6a56d65 17009476 wordpress_6.5.5+dfsg1.orig.tar.xz 10fbf935be8337ff9cf8c560566dd63463f47478 6923044 wordpress_6.5.5+dfsg1-1.debian.tar.xz 6591417b0438f0fa52216a51237e47cf8f46f9b4 7986 wordpress_6.5.5+dfsg1-1_amd64.buildinfo Checksums-Sha256: df5b90896a076d4bef62956895a0848ce6a8bf2a322aed18a36102a62c7cebc5 2420 wordpress_6.5.5+dfsg1-1.dsc 74bdd094cebcd2a95a796f0bc8c3e38983d37e909b563e9297459bc6342857ec 17009476 wordpress_6.5.5+dfsg1.orig.tar.xz b451a2be80bad89b79ffdcd5738987e2028f910037de23ac763aecb4f953dbc3 6923044 wordpress_6.5.5+dfsg1-1.debian.tar.xz ef4a36cbcdc64b60b729c1511546e84f8dda30b9b3c3ed311694021711d3496d 7986 wordpress_6.5.5+dfsg1-1_amd64.buildinfo Files: 53dae7d0fb54ec63f3239dda60858c02 2420 web optional wordpress_6.5.5+dfsg1-1.dsc 648514ad2bb8db3c153b2364de3a7d75 17009476 web optional wordpress_6.5.5+dfsg1.orig.tar.xz 9b6617d4df269810b32f6482af0e208c 6923044 web optional wordpress_6.5.5+dfsg1-1.debian.tar.xz 4144ad00159aa377adb146167f2c5d61 7986 web optional wordpress_6.5.5+dfsg1-1_amd64.buildinfo -----BEGIN PGP SIGNATURE----- iQIzBAEBCgAdFiEEXT3w9TizJ8CqeneiAiFmwP88hOMFAmaBJcgACgkQAiFmwP88 hOO5Kg/8CShVj6feqN5g53OICjwIzgqTNJBBaD3PCbAWTytc+FgRsec5hMHR0q+s yHSxB/tgczcH4Q/tmPvL7lJ8Bj5+Jy+kAU48K5F0wUt9pb+ldnayPjBt39Bc+nGP RvLPPb3qyVSJapNIbrIb44OeG/P8BA4rKtm2T7LhUskTeYgq3TXH3ZM9R0U84Y/s d9yU2Aygh+W4qvyIcoDmx9GCtZbB9I+8a5vCcYUvNNLK06Y1/iHzRFttIZ+Uw6xZ cE1hVWmGG92bCztpUH3YGqC69k7dlJ2/NJYSmLoJZBSQTegtotFkzNGlbXJXq1bc vhkAPWLiKwtUgoBj+51QbPbZmJ2kWvgNCUph/xXovHR0M35LFIcOCdM0bmKZiMz0 FVq2K/93Ng4t/Nxs6hIZrCQmXaKuhy3rA3koKlM4qXYtsn7ptBniT9vuU++3V1NO ineuB7qF1DKFlhs/14gItheWnEVCbt6CqFh+6fwqe20M4r90cGAuTd6QYNjENu+3 7AcQRGYH9fhm7vhKXUhn2cuCBGDZAYec/2JJRgZZqc8NKMnaUymR0Q6+s3UY6S8s 8KU8vYZrRTCxB/KZZK5Nul5JBhszgIj+ax+rxnnXA/uFow246ZzkhR3mC5gDhDSe dfED41z984nziOXhxEQOj7MqyULw7bQ5QSEBBRukNZKSVu9OpDo= =9sRX -----END PGP SIGNATURE-----