[Bug 602772] Re: Sync mahara 1.2.5-1 (universe) from Debian unstable (main)

2010-07-08 Thread Jamie Strandboge
mahara (1.0.9-2ubuntu0.7) jaunty-security; urgency=low * SECURITY UPDATE: multiple cross-site scripting vulnerabilities - debian/patches/CVE-2010-1667.dpatch: upstream patch - CVE-2010-1667 * SECURITY UPDATE: multiple cross-site request forgery vulnerabilities - debian/patches/CVE

[Bug 602772] Re: Sync mahara 1.2.5-1 (universe) from Debian unstable (main)

2010-07-08 Thread Jamie Strandboge
mahara (1.1.5-1ubuntu0.3) karmic-security; urgency=low * SECURITY UPDATE: multiple cross-site scripting vulnerabilities - debian/patches/CVE-2010-1667.dpatch: upstream patch - CVE-2010-1667 * SECURITY UPDATE: multiple cross-site request forgery vulnerabilities - debian/patches/CVE

[Bug 602772] Re: Sync mahara 1.2.5-1 (universe) from Debian unstable (main)

2010-07-08 Thread Jamie Strandboge
mahara (1.2.4-1ubuntu0.1) lucid-security; urgency=low * SECURITY UPDATE: multiple cross-site scripting vulnerabilities - debian/patches/CVE-2010-1667.patch: upstream patch - CVE-2010-1667 * SECURITY UPDATE: multiple cross-site request forgery vulnerabilities - debian/patches/CVE-2

[Bug 602772] Re: Sync mahara 1.2.5-1 (universe) from Debian unstable (main)

2010-07-08 Thread Jamie Strandboge
Francois, thanks for the patches! I have uploaded these to our security queue and will publish them after they finish building. ** Changed in: mahara (Ubuntu Lucid) Status: New => Fix Committed ** Changed in: mahara (Ubuntu Jaunty) Status: New => Fix Committed ** Changed in: mahara

[Bug 602772] Re: Sync mahara 1.2.5-1 (universe) from Debian unstable (main)

2010-07-08 Thread Jamie Strandboge
2010-07-08 15:08:04 INFO - http://ftp.debian.org/debian/> [Updating] mahara (1.2.4-1 [Ubuntu] < 1.2.5-2 [Debian]) * Trying to add mahara... 2010-07-08 15:08:05 INFO - http://ftp.debian.org/debian/> 2010-07-08 15:08:05 INFO - http://ftp.debian.org/debian/> I: mahara [universe] -> mah

[Bug 602772] Re: Sync mahara 1.2.5-1 (universe) from Debian unstable (main)

2010-07-08 Thread Jamie Strandboge
** Also affects: mahara (Ubuntu Jaunty) Importance: Undecided Status: New ** Also affects: mahara (Ubuntu Karmic) Importance: Undecided Status: New ** Also affects: mahara (Ubuntu Lucid) Importance: Undecided Status: New ** Tags added: patch -- Sync mahara 1.2.5-1

[Bug 602772] Re: Sync mahara 1.2.5-1 (universe) from Debian unstable (main)

2010-07-07 Thread François Marier
I have just attached debdiffs for jaunty, karmic and lucid to fix all 5 CVE bugs (tested on each Ubuntu release). -- Sync mahara 1.2.5-1 (universe) from Debian unstable (main) https://bugs.launchpad.net/bugs/602772 You received this bug notification because you are a member of Ubuntu Bugs, which

[Bug 602772] Re: Sync mahara 1.2.5-1 (universe) from Debian unstable (main)

2010-07-07 Thread François Marier
** Patch added: "mahara_lucid.deb.diff" http://launchpadlibrarian.net/51555948/mahara_lucid.deb.diff -- Sync mahara 1.2.5-1 (universe) from Debian unstable (main) https://bugs.launchpad.net/bugs/602772 You received this bug notification because you are a member of Ubuntu Bugs, which is subscr

[Bug 602772] Re: Sync mahara 1.2.5-1 (universe) from Debian unstable (main)

2010-07-07 Thread François Marier
** Patch added: "mahara_karmic.deb.diff" http://launchpadlibrarian.net/51555947/mahara_karmic.deb.diff -- Sync mahara 1.2.5-1 (universe) from Debian unstable (main) https://bugs.launchpad.net/bugs/602772 You received this bug notification because you are a member of Ubuntu Bugs, which is subs

[Bug 602772] Re: Sync mahara 1.2.5-1 (universe) from Debian unstable (main)

2010-07-07 Thread François Marier
** Patch added: "mahara_jaunty.deb.diff" http://launchpadlibrarian.net/51555942/mahara_jaunty.deb.diff -- Sync mahara 1.2.5-1 (universe) from Debian unstable (main) https://bugs.launchpad.net/bugs/602772 You received this bug notification because you are a member of Ubuntu Bugs, which is subs

[Bug 602772] Re: Sync mahara 1.2.5-1 (universe) from Debian unstable (main)

2010-07-07 Thread François Marier
** This bug has been flagged as a security vulnerability -- Sync mahara 1.2.5-1 (universe) from Debian unstable (main) https://bugs.launchpad.net/bugs/602772 You received this bug notification because you are a member of Ubuntu Bugs, which is subscribed to Ubuntu. -- ubuntu-bugs mailing list ub