<?xml version="1.0" encoding="UTF-8"?><rss version="2.0"
	xmlns:content="http://purl.org/rss/1.0/modules/content/"
	xmlns:dc="http://purl.org/dc/elements/1.1/"
	xmlns:atom="http://www.w3.org/2005/Atom"
	>
<channel>
	<title>Comments on: security: wordpress 2.5.1 which fixes CVE-2008-1930</title>
	<atom:link href="http://blog.waja.info/2008/04/25/wordpress-251-which-fixes-cve-2008-1930/feed/" rel="self" type="application/rss+xml" />
	<link>http://blog.waja.info/2008/04/25/wordpress-251-which-fixes-cve-2008-1930/</link>
	<description>Just a place to be!</description>
	<pubDate>Thu, 24 Jul 2008 06:35:56 +0000</pubDate>
	<generator>http://wordpress.org/?v=2.5.1</generator>
		<item>
		<title>By: cyco</title>
		<link>http://blog.waja.info/2008/04/25/wordpress-251-which-fixes-cve-2008-1930/#comment-25322</link>
		<dc:creator>cyco</dc:creator>
		<pubDate>Mon, 28 Apr 2008 07:54:37 +0000</pubDate>
		<guid isPermaLink="false">http://blog.waja.info/?p=160#comment-25322</guid>
		<description>Hi Hendry,

yes, I did read the CVE and I recognized that there maybe a workaround. But not in all cases it can be used.

I had two reasons to not write to the relevant bug:
I did only rebuild the package with new upstream source, so there was nothing to change with packaging.
I did the new package just hours before starting a one week &lt;a href="http://blog.waja.info/2008/04/26/off-for-vacation/" target="new" rel="nofollow"&gt;vacation&lt;/a&gt;, which you probable noticed, so I'm not able to reply to anything. You might think, okay .. actually he can, but I had an unplanned interruption.

The problem about getting security updates into stable is an other problem. Since the release policy is to just fix security bugs (backporting things), which might problematic with even wordpress.
There was an idea about a webapps repository with different release cycles. Aba and ganneff stated, this might be a good idea, but this have to be done by anybody, for example write down a policy and get it discussed ... infrastructure seems not the problem here.
Since I might have less time in short term, I scheduled it for after post lenny, if nobody other get the ball.

And counting security bugs for ikiwiki is less fun, since it have significant less (security-)bugcount. :)</description>
		<content:encoded><![CDATA[<p>Hi Hendry,</p>
<p>yes, I did read the CVE and I recognized that there maybe a workaround. But not in all cases it can be used.</p>
<p>I had two reasons to not write to the relevant bug:<br />
I did only rebuild the package with new upstream source, so there was nothing to change with packaging.<br />
I did the new package just hours before starting a one week <a href="http://blog.waja.info/2008/04/26/off-for-vacation/" target="new" rel="nofollow">vacation</a>, which you probable noticed, so I&#8217;m not able to reply to anything. You might think, okay .. actually he can, but I had an unplanned interruption.</p>
<p>The problem about getting security updates into stable is an other problem. Since the release policy is to just fix security bugs (backporting things), which might problematic with even wordpress.<br />
There was an idea about a webapps repository with different release cycles. Aba and ganneff stated, this might be a good idea, but this have to be done by anybody, for example write down a policy and get it discussed &#8230; infrastructure seems not the problem here.<br />
Since I might have less time in short term, I scheduled it for after post lenny, if nobody other get the ball.</p>
<p>And counting security bugs for ikiwiki is less fun, since it have significant less (security-)bugcount. :)</p>
]]></content:encoded>
	</item>
	<item>
		<title>By: Kai Hendry</title>
		<link>http://blog.waja.info/2008/04/25/wordpress-251-which-fixes-cve-2008-1930/#comment-25296</link>
		<dc:creator>Kai Hendry</dc:creator>
		<pubDate>Sat, 26 Apr 2008 18:23:52 +0000</pubDate>
		<guid isPermaLink="false">http://blog.waja.info/?p=160#comment-25296</guid>
		<description>Hi guys,

Did any of you bother to read the CVE? Most people don't allow new users to register. So this risk is pretty low...

If you do prepare packages before the maintainer does, please mail the relevant bug:
http://bugs.debian.org/cgi-bin/bugreport.cgi?bug=477910
So we can double check things. :)

Wordpress itself, users and I as an ex-maintainer do care a lot about security. Truth is software of this complexity and popularity do get security bugs. Shocking isn't it?!

Sadly I've had a lot of problems getting security updates in Debian stable. Also I've had issues getting simple upload rights in Debian. So sorry for the delays. :( I tried my best, but a small minority of bigots in Debian can be too exhausting over the years! :)

Why we're here, why don't you count the security bugs on another excellent piece of Web software, like ikiwiki?</description>
		<content:encoded><![CDATA[<p>Hi guys,</p>
<p>Did any of you bother to read the CVE? Most people don&#8217;t allow new users to register. So this risk is pretty low&#8230;</p>
<p>If you do prepare packages before the maintainer does, please mail the relevant bug:<br />
<a href="http://bugs.debian.org/cgi-bin/bugreport.cgi?bug=477910" rel="nofollow">http://bugs.debian.org/cgi-bin/bugreport.cgi?bug=477910</a><br />
So we can double check things. :)</p>
<p>Wordpress itself, users and I as an ex-maintainer do care a lot about security. Truth is software of this complexity and popularity do get security bugs. Shocking isn&#8217;t it?!</p>
<p>Sadly I&#8217;ve had a lot of problems getting security updates in Debian stable. Also I&#8217;ve had issues getting simple upload rights in Debian. So sorry for the delays. :( I tried my best, but a small minority of bigots in Debian can be too exhausting over the years! :)</p>
<p>Why we&#8217;re here, why don&#8217;t you count the security bugs on another excellent piece of Web software, like ikiwiki?</p>
]]></content:encoded>
	</item>
	<item>
		<title>By: cyco</title>
		<link>http://blog.waja.info/2008/04/25/wordpress-251-which-fixes-cve-2008-1930/#comment-25287</link>
		<dc:creator>cyco</dc:creator>
		<pubDate>Sat, 26 Apr 2008 09:17:51 +0000</pubDate>
		<guid isPermaLink="false">http://blog.waja.info/?p=160#comment-25287</guid>
		<description>I guess that won't be a reason, since the most users of such an application doesn't care (much) about security. From my side as hosting provider the best way is to stay with newest version of the software and keep an eye on security relevant sources.</description>
		<content:encoded><![CDATA[<p>I guess that won&#8217;t be a reason, since the most users of such an application doesn&#8217;t care (much) about security. From my side as hosting provider the best way is to stay with newest version of the software and keep an eye on security relevant sources.</p>
]]></content:encoded>
	</item>
	<item>
		<title>By: Anonymous</title>
		<link>http://blog.waja.info/2008/04/25/wordpress-251-which-fixes-cve-2008-1930/#comment-25279</link>
		<dc:creator>Anonymous</dc:creator>
		<pubDate>Sat, 26 Apr 2008 01:10:30 +0000</pubDate>
		<guid isPermaLink="false">http://blog.waja.info/?p=160#comment-25279</guid>
		<description>How many security vulnerabilities does wordpress need to have before people stop using it?</description>
		<content:encoded><![CDATA[<p>How many security vulnerabilities does wordpress need to have before people stop using it?</p>
]]></content:encoded>
	</item>
</channel>
</rss>
