The following Fedora EPEL 6 Security updates need testing: Age URL 9 https://bodhi.fedoraproject.org/updates/FEDORA-EPEL-2020-b21ed088ad tcpreplay-4.3.3-3.el6 7 https://bodhi.fedoraproject.org/updates/FEDORA-EPEL-2020-ca0361c919 lout-3.40-18.el6
The following builds have been pushed to Fedora EPEL 6 updates-testing
wordpress-5.1.7-1.el6
Details about builds:
================================================================================ wordpress-5.1.7-1.el6 (FEDORA-EPEL-2020-52c3f02cdc) Blog tool and publishing platform -------------------------------------------------------------------------------- Update Information:
**WordPress 5.1.7 Security Release** **Security Updates** * Props to Alex Concha of the WordPress Security Team for their work in hardening deserialization requests. * Props to David Binovec on a fix to disable spam embeds from disabled sites on a multisite network. * Thanks to Marc Montas from Sucuri for reporting an issue that could lead to XSS from global variables. * Thanks to Justin Tran who reported an issue surrounding privilege escalation in XML-RPC. He also found and disclosed an issue around privilege escalation around post commenting via XML-RPC. * Props to Omar Ganiev who reported a method where a DoS attack could lead to RCE. * Thanks to Karim El Ouerghemmi from RIPS who disclosed a method to store XSS in post slugs. * Thanks to Slavco for reporting, and confirmation from Karim El Ouerghemmi, a method to bypass protected meta that could lead to arbitrary file deletion. * Thanks to Erwan LR from WPScan who responsibly disclosed a method that could lead to CSRF. * And a special thanks to @zieladam who was integral in many of the releases and patches during this release. -------------------------------------------------------------------------------- ChangeLog:
* Fri Oct 30 2020 Remi Collet remi@remirepo.net - 5.1.7-1 - WordPress 5.1.7 Security Release --------------------------------------------------------------------------------
epel-devel@lists.fedoraproject.org