-----BEGIN PGP SIGNED MESSAGE----- Hash: SHA512 Format: 1.8 Date: Wed, 06 Jul 2016 20:52:08 +1000 Source: wordpress Binary: wordpress wordpress-l10n wordpress-theme-twentyfifteen wordpress-theme-twentyfourteen wordpress-theme-twentythirteen Architecture: source all Version: 4.1+dfsg-1+deb8u9 Distribution: jessie-security Urgency: high Maintainer: Craig Small <csmall@debian.org> Changed-By: Craig Small <csmall@debian.org> Description: wordpress - weblog manager wordpress-l10n - weblog manager - language files wordpress-theme-twentyfifteen - weblog manager - twentytfifteen theme files wordpress-theme-twentyfourteen - weblog manager - twentyfourteen theme files wordpress-theme-twentythirteen - weblog manager - twentythirteen theme files Closes: 828225 Changes: wordpress (4.1+dfsg-1+deb8u9) jessie-security; urgency=high . * Backport patches from 4.5.3/4.1.12 Closes: #828225 * Fixes CVE-2016-5834, CVE-2016-5838, CVE-2016-5839 * Changeset 37762 admin auth redirect * Changeset 37773 Customizer urls CVE-2016-5832 * Changeset 37781 Category check CVE-2016-5837 * Changeset 37790 admin escape attach * Changeset 37800 Revision capability CVE-2016-5835 * Changeset 37815 escape url permalinks * Changeset 37818 media extensionless filenames * Changeset 32387 CVE-2015-8834 XSS in comments Checksums-Sha1: 124196667d49db39e7df0c9b017afd6e8eda13a1 2533 wordpress_4.1+dfsg-1+deb8u9.dsc c15cafdda068fbc8719b7999f3d4644798908c06 6073448 wordpress_4.1+dfsg-1+deb8u9.debian.tar.xz fe75969c022c39ea139cdb810ff0effdcf6643c4 3163088 wordpress_4.1+dfsg-1+deb8u9_all.deb ea4fafd23e1a86fa015b70d37002c867d4d169eb 4198352 wordpress-l10n_4.1+dfsg-1+deb8u9_all.deb 577c868bbe7d933b4bb6f24364c5877e926ea460 502458 wordpress-theme-twentyfifteen_4.1+dfsg-1+deb8u9_all.deb 5cd040202b221775a81ce3307860d243aa44ea30 801462 wordpress-theme-twentyfourteen_4.1+dfsg-1+deb8u9_all.deb 1e9a271bb45f812c8f8037d4d2ead63443678443 320668 wordpress-theme-twentythirteen_4.1+dfsg-1+deb8u9_all.deb Checksums-Sha256: d48bc4c3ecb48c21de009c073cddb9925e804a0c514383e19e4149e9998ae740 2533 wordpress_4.1+dfsg-1+deb8u9.dsc 9e125dca5ff54fdbbc253c7cc9583a7639bc619303e5e65668458bb687146bac 6073448 wordpress_4.1+dfsg-1+deb8u9.debian.tar.xz 3ecd66b971d01b9d4d5c015eda1d32787a9954417053eb12bce2eec34e5c48e4 3163088 wordpress_4.1+dfsg-1+deb8u9_all.deb 8687dbccf823eefb7613beff216d062d338124fdd6d7410628021ad77771d457 4198352 wordpress-l10n_4.1+dfsg-1+deb8u9_all.deb d92adf2cde9c0c2346c96b028dc549636dec1aedf48fbc2280da56924955a701 502458 wordpress-theme-twentyfifteen_4.1+dfsg-1+deb8u9_all.deb 64bfe534d341989b20c3d0fad74ac805e75203b9b1e957a8cce48ae86449e315 801462 wordpress-theme-twentyfourteen_4.1+dfsg-1+deb8u9_all.deb d5b92933e71795753901ba2c7b656da307e8d97e1d265ff984bdd3a9cca651b8 320668 wordpress-theme-twentythirteen_4.1+dfsg-1+deb8u9_all.deb Files: 0339500ce48a87719655d4cf6a0140f6 2533 web optional wordpress_4.1+dfsg-1+deb8u9.dsc a346c07a755bb8d478c7bf271da694f5 6073448 web optional wordpress_4.1+dfsg-1+deb8u9.debian.tar.xz bf4f516e37c88086bbe6b877b15c1661 3163088 web optional wordpress_4.1+dfsg-1+deb8u9_all.deb df8bcbcbf09c2a7efc8406b10b04bb51 4198352 localization optional wordpress-l10n_4.1+dfsg-1+deb8u9_all.deb 13615c59d2e256a964b5d94d945962a5 502458 web optional wordpress-theme-twentyfifteen_4.1+dfsg-1+deb8u9_all.deb 7064483fe544794f99cc3d14f6eaf4d9 801462 web optional wordpress-theme-twentyfourteen_4.1+dfsg-1+deb8u9_all.deb f2b2c8b307c6a0b4e4e96564cca58096 320668 web optional wordpress-theme-twentythirteen_4.1+dfsg-1+deb8u9_all.deb -----BEGIN PGP SIGNATURE----- Version: GnuPG v1 iQIcBAEBCgAGBQJXoXJ6AAoJEAVMuPMTQ89EGIUP/jChmPsgw7+bWPS+BNaCX1zz U/AblX+IF2ljzJdwaE0+5dzAUaxpJiQPz2h9Pr8X5IZe9puy3sPXPafbYc+FCkkI uXn59qoUvOlrjXUA9OACjxIDAuXKqSntSECDLxkW9Jcz0kotcNcANIAilIdklpbj LwkMdDvbhXWYHVXs3qqzbLB3XNLB+naS8q/gJIUnKqPyFXC4GYBMQRdrBMcKJJKf OdtHOAgqG/TyWUIXGmJXD6RyrO/l7U7dGPpi4cFK04ooR8fykBBKPsdc3g4lSM3b j18PjQt06+CTn1kWFmVRBD5jj8JascdG1jzvIhrYfHZdCuGZiF+1pu1jZfNprVxD ZXrzXwamXNEPtNxZoz2UivzhTAck2Gj/CdofGwTK9LJz11j0W7a6ZwtJ+2FNyQSo SKkjanQx0X3T04DXB4XJUIZ0juveSF8Cdw4tCzioK4hdcZu/lON7W6r0/ljeFC1f BnaDPu2kF4C4wdBnENcEJJvp6AQk5s1LxzIwvg74hwlZqJ9qhhUoSiEQGqmcK/qZ gOWwKpmUZoST2W9nzOKRbYgFethv94Y5EJIian2ajFXpqHV6/9Aqgn85Z/tcBzs5 ydpq/H+TFKTJabqrco91E+j1VQpn+4jhLCmgMVaE7SBFACzEohZieogPJVjT8U7j dOxwZED3xibGSIDhj2Bb =uMkn -----END PGP SIGNATURE-----