Bug#606311: Acknowledgement (movabletype-opensource: Unspecified XSS and SQL injection vulnerabilities fixed in 4.35)

2011-01-08 Thread Adam D. Barratt
On Wed, 2011-01-05 at 22:40 +, Dominic Hargreaves wrote: On Sun, Dec 12, 2010 at 06:13:12PM +, Adam D. Barratt wrote: On Fri, 2010-12-10 at 22:33 +, Dominic Hargreaves wrote: I've pushed the diff to git now:

Bug#606311: Acknowledgement (movabletype-opensource: Unspecified XSS and SQL injection vulnerabilities fixed in 4.35)

2011-01-05 Thread Dominic Hargreaves
On Sun, Dec 12, 2010 at 06:13:12PM +, Adam D. Barratt wrote: On Fri, 2010-12-10 at 22:33 +, Dominic Hargreaves wrote: I've pushed the diff to git now: http://git.debian.org/?p=pkg-mt-om/movabletype-opensource.git;a=commit;h=66daeefb9288a35e45a0634d5419fb0cf28c8d5f and built/basic

Bug#606311: Acknowledgement (movabletype-opensource: Unspecified XSS and SQL injection vulnerabilities fixed in 4.35)

2010-12-12 Thread Adam D. Barratt
On Fri, 2010-12-10 at 22:33 +, Dominic Hargreaves wrote: I've pushed the diff to git now: http://git.debian.org/?p=pkg-mt-om/movabletype-opensource.git;a=commit;h=66daeefb9288a35e45a0634d5419fb0cf28c8d5f and built/basic sanity checked the resulting packages. It's quite possibly not

Bug#606311: Acknowledgement (movabletype-opensource: Unspecified XSS and SQL injection vulnerabilities fixed in 4.35)

2010-12-10 Thread Dominic Hargreaves
On Wed, Dec 08, 2010 at 11:15:24PM +, Dominic Hargreaves wrote: On Wed, Dec 08, 2010 at 07:51:50PM +, Dominic Hargreaves wrote: The changes can be summarised roughly as follows: lib/MT/App/Search.pm| 22 +- Input checking Patch does

Bug#606311: Acknowledgement (movabletype-opensource: Unspecified XSS and SQL injection vulnerabilities fixed in 4.35)

2010-12-08 Thread Dominic Hargreaves
Ignoring files that have only changed SVN ID, removed files which were already ignored by debian/rules (mt-static/support/dashboard/stats) and changes which only bump the version number, we have the following changes between MTOS 4.34 and 4.35: lib/MT/App/Search.pm| 22

Bug#606311: Acknowledgement (movabletype-opensource: Unspecified XSS and SQL injection vulnerabilities fixed in 4.35)

2010-12-08 Thread Dominic Hargreaves
found 606311 4.2.3-1+lenny1 thanks On Wed, Dec 08, 2010 at 07:51:50PM +, Dominic Hargreaves wrote: The changes can be summarised roughly as follows: lib/MT/App/Search.pm| 22 +- Input checking Patch does not apply to 4.2.3-1+lenny1