The following Fedora EPEL 6 Security updates need testing: Age URL 12 https://bodhi.fedoraproject.org/updates/FEDORA-EPEL-2020-b21ed088ad tcpreplay-4.3.3-3.el6 10 https://bodhi.fedoraproject.org/updates/FEDORA-EPEL-2020-ca0361c919 lout-3.40-18.el6 The following builds have been pushed to Fedora EPEL 6 updates-testing wordpress-5.1.8-1.el6 Details about builds: ================================================================================ wordpress-5.1.8-1.el6 (FEDORA-EPEL-2020-6bc42544ca) Blog tool and publishing platform -------------------------------------------------------------------------------- Update Information: **WordPress 5.1.8 Maintenance Release** This maintenance release fixes an issue introduced in WordPress 5.1.7 which makes it impossible to install WordPress on a brand new website that does not have a database connection configured. ---- **WordPress 5.1.7 Security Release** **Security Updates** * Props to Alex Concha of the WordPress Security Team for their work in hardening deserialization requests. * Props to David Binovec on a fix to disable spam embeds from disabled sites on a multisite network. * Thanks to Marc Montas from Sucuri for reporting an issue that could lead to XSS from global variables. * Thanks to Justin Tran who reported an issue surrounding privilege escalation in XML-RPC. He also found and disclosed an issue around privilege escalation around post commenting via XML-RPC. * Props to Omar Ganiev who reported a method where a DoS attack could lead to RCE. * Thanks to Karim El Ouerghemmi from RIPS who disclosed a method to store XSS in post slugs. * Thanks to Slavco for reporting, and confirmation from Karim El Ouerghemmi, a method to bypass protected meta that could lead to arbitrary file deletion. * Thanks to Erwan LR from WPScan who responsibly disclosed a method that could lead to CSRF. * And a special thanks to @zieladam who was integral in many of the releases and patches during this release. -------------------------------------------------------------------------------- ChangeLog: * Mon Nov 2 2020 Remi Collet <remi@xxxxxxxxxxxx> - 5.1.8-1 - WordPress 5.1.8 Maintenance Release * Fri Oct 30 2020 Remi Collet <remi@xxxxxxxxxxxx> - 5.1.7-1 - WordPress 5.1.7 Security Release -------------------------------------------------------------------------------- _______________________________________________ epel-devel mailing list -- epel-devel@xxxxxxxxxxxxxxxxxxxxxxx To unsubscribe send an email to epel-devel-leave@xxxxxxxxxxxxxxxxxxxxxxx Fedora Code of Conduct: https://docs.fedoraproject.org/en-US/project/code-of-conduct/ List Guidelines: https://fedoraproject.org/wiki/Mailing_list_guidelines List Archives: https://lists.fedoraproject.org/archives/list/epel-devel@xxxxxxxxxxxxxxxxxxxxxxx