Viewing 12 replies - 1 through 12 (of 12 total)
  • Not sure where you are reading that from, but as far as I can see it is not anywhere on the actual web… and there is no WordPress 4.2.5…

    https://codex.www.ads-software.com/WordPress_Versions

    I think 4.2.5 must be the security patches from today’s 4.3.1 release. I have one site with auto-upgrades turned on that hadn’t been updated to 4.3 yet and it auto upgraded to 4.2.5 this morning. https://codex.www.ads-software.com/Version_4.2.5 is just an alias for 4.3.1 release.

    I’m actually trying to figure out how I can apply this 4.2.5 patch manually (without having to go 4.3–I have some plugin compatibility issues).

    Ahah interesting! I had not heard about that.

    This page may help… Looks like it has a download for 4.2.5 so you are right! I imagine if you did want to just update you could probably do a manual update via FTP using those files – though don’t quote me.

    https://www.ads-software.com/download/release-archive/

    Thread Starter fastfasterfastest

    (@fastfasterfastest)

    I am not looking for the download of 4.2.5 – I am looking for the release notes for 4.2.5.

    The release notes for 4.2.4 are readily available at https://codex.www.ads-software.com/Version_4.2.4. But on the “related page” for 4.2.5, information about 4.3.1 is instead displayed. Thus this post with subject “release notes for 4.2.5 missing”

    “Version 4.2.5 addressed some security issues and fixed 2 bugs.”

    “4.3.1 fixes two cross-site scripting vulnerabilities …and a potential privilege escalation… contains fixes for 26 bugs from 4.3”

    > I’m actually trying to figure out how I can apply this 4.2.5 patch manually

    But I thought you said you wanted to update? Fair enough, sorry I personally can’t help any further.

    Thread Starter fastfasterfastest

    (@fastfasterfastest)

    >I thought you said

    I did not say that, someone else jumped in and said that. FYI, my question is in the original post above: Where can I find the release notes for 4.2.5?

    Sorry! Haha I thought I was conversing with just one person, I didn’t look at the avatar for some reason.

    Seems like you have the correct URL… so perhaps they will add them at some point.

    Sorry, I didn’t mean to hijack your thread. I was able to checkout the 4.2.5 changes from the git repo, so I can verify that it is indeed a security patch that includes fixes for the couple of XSS bugs addressed in 4.3.1. I think the release notes for 4.3.1 serve as the de facto ones for 4.2.5. If you’re interested in the specific changes to core, I’d be happy to provide them for you here.

    Thread Starter fastfasterfastest

    (@fastfasterfastest)

    >Seems like you have the correct URL… so perhaps they will add them at some point.

    I appreciate you are trying to help.
    And yes, my post was both a question and an attempt to alert the powers-at-be that something is missing and/or the wrong info is mistakenly posted for 4.2.5.

    Thread Starter fastfasterfastest

    (@fastfasterfastest)

    >I think the release notes for 4.3.1 serve as the de facto ones for 4.2.5

    Since there are specific release notes for 4.2.4, one might think there will/should be specific release notes for 4.2.5 as well. I’ll sit back and wait and see if that page gets updated.

    I think it’s just not very clear that there’s a practice of backporting patches to older versions with critical security fixes and just alias that “point version” (i.e., 4.2-point-5) to the main release notes (4.3.1 in this case).

    It looks like the significant changes from 4.2.4 to 4.2.5 were:
    Some security/code cleanup to:

    /wp-admin/includes/ajax-actions.php
    /wp-admin/includes/class-wp-ms-users-list-table.php
    /wp-admin/includes/class-wp-users-list-table.php
    /wp-includes/capabilities.php
    /wp-includes/media.php
    /wp-includes/shortcodes.php

    And some new logic for sticky posts in:
    /wp-includes/class-wp-xmlrpc-server.php

    Thread Starter fastfasterfastest

    (@fastfasterfastest)

    It appears the page in question, https://codex.www.ads-software.com/Version_4.2.5, has now been updated.

Viewing 12 replies - 1 through 12 (of 12 total)
  • The topic ‘release notes for 4.2.5 missing’ is closed to new replies.