geek ramblings :: New WordPress Releases: 2.0.10 and 2.1.3

April 4, 2007 by Chris Mosby · Leave a Comment
Filed under: Tech Links 

geek ramblings :: New WordPress Releases: 2.0.10 and 2.1.3

New WordPress Releases: 2.0.10 and 2.1.3

That’s right, two shiny new bugfix/security updates.
One for the 2.0 branch and one for the 2.1 branch. There are some small
bugfixes in both of these versions, but the main reason to upgrade is
for the security fixes (I’m going to write more on that subject later).

Visit the downloads page for version 2.1.3, and the Release Archive for version 2.0.10.

Watch later this month for the release of WordPress 2.2. This
upcoming release will add several new features, including built-in
support for tags(!), Atom 1.0 feeds for posts and comments, some
preliminary Atom Publishing Protocol support (I’ve been working on
that), several new XML-RPC
methods, widget support in the default templates, performance
enhancements, and several other things that I can’t think of right now.
Obviously, there will be more details available at the time of the
official release, which is slated for April 22.

Powered by ScribeFire.

WordPress › Blog » WordPress 2.1.1 dangerous, Upgrade to 2.1.2

Patch now!!

WordPress › Blog » WordPress 2.1.1 dangerous, Upgrade to 2.1.2

March 2, 2007

WordPress 2.1.1 dangerous, Upgrade to 2.1.2

By Matt. Filed under Releases.

Long
story short: If you downloaded WordPress 2.1.1 within the past 3-4
days, your files may include a security exploit that was added by a
cracker, and you should upgrade all of your files to 2.1.2 immediately.

Longer explanation: This morning we received a note to our security
mailing address about unusual and highly exploitable code in WordPress.
The issue was investigated, and it appeared that the 2.1.1 download had
been modified from its original code. We took the website down
immediately to investigate what happened.

It was determined that a cracker had gained user-level access to one
of the servers that powers wordpress.org, and had used that access to
modify the download file. We have locked down that server for further
forensics, but at this time it appears that the 2.1.1 download was the
only thing touched by the attack. They modified two files in WP to
include code that would allow for remote PHP execution.

This is the kind of thing you pray never happens, but it did and now
we’re dealing with it as best we can. Although not all downloads of
2.1.1 were affected, we’re declaring the entire version dangerous and
have released a new version 2.1.2
that includes minor updates and entirely verified files. We are also
taking lots of measures to ensure something like this can’t happen
again, not the least of which is minutely external verification of the
download package so we’ll know immediately if something goes wrong for
any reason.

Finally, we reset passwords for a number of users with SVN and other access, so you may need to reset your password on the forums before you can login again.

What You Can Do to Help

If your blog is running 2.1.1, please upgrade immediately and do a
full overwrite of your old files, especially those in wp-includes.
Check out your friends blogs and if any of them are running 2.1.1 drop
them a note and, if you can, pitch in and help them with the upgrade.

If you are a web host or network administrator, block access to
“theme.php” and “feed.php”, and any query string with “ix=” or “iz=” in
it. If you’re a customer at a web host, you may want to send them a
note to let them know about this release and the above information.

Thanks to Ryan, Barry, Donncha, Mark, Michael, and Dougal for
working through the night to figure out and address this problem, and
thanks to Ivan Fratric for reporting it in the first place.

Questions and Answers

Because of the highly unusual nature of this event and release, we’ve set up an email address 21securityfaq@wordpress.org that you can email questions to, and we’ll be updating this entry with more information throughout the day.

Is version 2.0 affected?

No downloads were altered except 2.1.1, so if you’ve downloaded any version of 2.0 you should be fine.

What if we update from SVN?

Nothing in the Subversion repository was touched, so if you upgrade
and maintain your blog via SVN there is no chance you downloaded the
corrupted release file.

Technorati Tags: , , ,

powered by performancing firefox

WordPress › Blog » New Releases: 2.1.1 and 2.0.9

February 21, 2007 by Chris Mosby · Leave a Comment
Filed under: Tech Links, Tech Stuff 

WordPress › Blog » New Releases: 2.1.1 and 2.0.9

By Matt. Filed under Releases.
   

We’ve got a new bugfix and security release for both of our actively maintained branches of WordPress. Version 2.1.1 includes about 30 bug fixes, mostly minor things around encoding, XML-RPC, the object cache, and HTML code. It’s available for immediate download on our download page.

Version 2.0.9 only includes the security update, which was around the code we use to prevent XSS. You can download it from our release archive. As a reminder, we’ve committed to proving security updates to 2.0 through 2010, but all new features and development are going into the newer branch, which is at this time 2.1.

This is a low-to-medium priority update recommended for all WordPress users. After the break is a list of changed files.

Files changed in 2.1.1 from 2.1:

    * wp-includes/post-template.php

    * wp-includes/cache.php

    * wp-includes/formatting.php

    * wp-includes/category.php

    * wp-includes/post.php

    * wp-includes/version.php

    * wp-includes/js/scriptaculous/wp-scriptaculous.js

    * wp-includes/js/tinymce/tiny_mce_config.php

    * wp-includes/js/tinymce/wp-mce-help.php

    * wp-includes/js/tinymce/tiny_mce_gzip.php

    * wp-includes/capabilities.php

    * wp-includes/cron.php

    * wp-includes/functions.php

    * wp-includes/bookmark-template.php

    * xmlrpc.php

    * wp-admin/admin-ajax.php

    * wp-admin/admin-functions.php

    * wp-admin/custom-header.php

    * wp-admin/options-general.php

    * wp-admin/edit.php

    * wp-admin/index-extra.php

    * wp-admin/options-reading.php

Files changed from 2.0.7 to 2.0.9 (version 2.0.8 was tagged for Debian, but never announced):

    * wp-includes/cache.php

    * wp-includes/wp-db.php

    * wp-includes/version.php

    * wp-includes/js/tinymce/wp-mce-help.php

    * wp-includes/js/tinymce/tiny_mce_gzip.php

    * wp-includes/classes.php

    * wp-includes/functions.php

    * wp-includes/rss-functions.php

    * readme.html

    * wp-admin/edit-form-advanced.php

    * wp-admin/link-import.php

    * wp-admin/link-categories.php

    * wp-admin/user-edit.php

    * wp-admin/options-permalink.php

powered by performancing firefox

Get Adobe Flash playerPlugin by wpburn.com wordpress themes