[Bug 602772] Re: Sync mahara 1.2.5-1 (universe) from Debian unstable (main)

2010-07-08 Thread Jamie Strandboge
** Also affects: mahara (Ubuntu Jaunty) Importance: Undecided Status: New ** Also affects: mahara (Ubuntu Karmic) Importance: Undecided Status: New ** Also affects: mahara (Ubuntu Lucid) Importance: Undecided Status: New ** Tags added: patch -- Sync mahara

[Bug 602772] Re: Sync mahara 1.2.5-1 (universe) from Debian unstable (main)

2010-07-08 Thread Jamie Strandboge
2010-07-08 15:08:04 INFO - mahara_1.2.5.orig.tar.gz: downloading from http://ftp.debian.org/debian/ [Updating] mahara (1.2.4-1 [Ubuntu] 1.2.5-2 [Debian]) * Trying to add mahara... 2010-07-08 15:08:05 INFO - mahara_1.2.5-2.dsc: downloading from http://ftp.debian.org/debian/ 2010-07-08

[Bug 602772] Re: Sync mahara 1.2.5-1 (universe) from Debian unstable (main)

2010-07-08 Thread Jamie Strandboge
Francois, thanks for the patches! I have uploaded these to our security queue and will publish them after they finish building. ** Changed in: mahara (Ubuntu Lucid) Status: New = Fix Committed ** Changed in: mahara (Ubuntu Jaunty) Status: New = Fix Committed ** Changed in: mahara

[Bug 602772] Re: Sync mahara 1.2.5-1 (universe) from Debian unstable (main)

2010-07-08 Thread Jamie Strandboge
mahara (1.2.4-1ubuntu0.1) lucid-security; urgency=low * SECURITY UPDATE: multiple cross-site scripting vulnerabilities - debian/patches/CVE-2010-1667.patch: upstream patch - CVE-2010-1667 * SECURITY UPDATE: multiple cross-site request forgery vulnerabilities -

[Bug 602772] Re: Sync mahara 1.2.5-1 (universe) from Debian unstable (main)

2010-07-08 Thread Jamie Strandboge
mahara (1.1.5-1ubuntu0.3) karmic-security; urgency=low * SECURITY UPDATE: multiple cross-site scripting vulnerabilities - debian/patches/CVE-2010-1667.dpatch: upstream patch - CVE-2010-1667 * SECURITY UPDATE: multiple cross-site request forgery vulnerabilities -

[Bug 602772] Re: Sync mahara 1.2.5-1 (universe) from Debian unstable (main)

2010-07-08 Thread Jamie Strandboge
mahara (1.0.9-2ubuntu0.7) jaunty-security; urgency=low * SECURITY UPDATE: multiple cross-site scripting vulnerabilities - debian/patches/CVE-2010-1667.dpatch: upstream patch - CVE-2010-1667 * SECURITY UPDATE: multiple cross-site request forgery vulnerabilities -

[Bug 602772] Re: Sync mahara 1.2.5-1 (universe) from Debian unstable (main)

2010-07-07 Thread François Marier
** This bug has been flagged as a security vulnerability -- Sync mahara 1.2.5-1 (universe) from Debian unstable (main) https://bugs.launchpad.net/bugs/602772 You received this bug notification because you are a member of Ubuntu Bugs, which is subscribed to Ubuntu. -- ubuntu-bugs mailing list

[Bug 602772] Re: Sync mahara 1.2.5-1 (universe) from Debian unstable (main)

2010-07-07 Thread François Marier
** Patch added: mahara_jaunty.deb.diff http://launchpadlibrarian.net/51555942/mahara_jaunty.deb.diff -- Sync mahara 1.2.5-1 (universe) from Debian unstable (main) https://bugs.launchpad.net/bugs/602772 You received this bug notification because you are a member of Ubuntu Bugs, which is

[Bug 602772] Re: Sync mahara 1.2.5-1 (universe) from Debian unstable (main)

2010-07-07 Thread François Marier
** Patch added: mahara_karmic.deb.diff http://launchpadlibrarian.net/51555947/mahara_karmic.deb.diff -- Sync mahara 1.2.5-1 (universe) from Debian unstable (main) https://bugs.launchpad.net/bugs/602772 You received this bug notification because you are a member of Ubuntu Bugs, which is

[Bug 602772] Re: Sync mahara 1.2.5-1 (universe) from Debian unstable (main)

2010-07-07 Thread François Marier
** Patch added: mahara_lucid.deb.diff http://launchpadlibrarian.net/51555948/mahara_lucid.deb.diff -- Sync mahara 1.2.5-1 (universe) from Debian unstable (main) https://bugs.launchpad.net/bugs/602772 You received this bug notification because you are a member of Ubuntu Bugs, which is

[Bug 602772] Re: Sync mahara 1.2.5-1 (universe) from Debian unstable (main)

2010-07-07 Thread François Marier
I have just attached debdiffs for jaunty, karmic and lucid to fix all 5 CVE bugs (tested on each Ubuntu release). -- Sync mahara 1.2.5-1 (universe) from Debian unstable (main) https://bugs.launchpad.net/bugs/602772 You received this bug notification because you are a member of Ubuntu Bugs, which