-----BEGIN PGP SIGNED MESSAGE----- Hash: SHA256 Format: 1.8 Date: Sun, 18 Dec 2011 23:19:40 +0000 Source: mediawiki Binary: mediawiki mediawiki-math Architecture: hppa Version: 1:1.12.0-2lenny9 Distribution: lenny-security Urgency: low Maintainer: hppa Build Daemon (peri) Changed-By: Jonathan Wiltshire Description: mediawiki - website engine for collaborative work mediawiki-math - math rendering plugin for MediaWiki Closes: 650434 Changes: mediawiki (1:1.12.0-2lenny9) oldstable-security; urgency=low . * Security fixes from upstream (Closes: #650434): CVE-2011-4360 - page titles on private wikis could be exposed bypassing different page ids to index.php CVE-2011-4361 - action=ajax requests were dispatched to the relevant function without any read permission checks being done CVE-2011-1578 - XSS for IE <= 6 CVE-2011-1579 - CSS validation error in wikitext parser CVE-2011-1580 - access control checks on transwiki import feature CVE-2011-1587 - fix incomplete patch for CVE-2011-1578 Checksums-Sha1: 79545bc03df886fa1668061ded77dca0b2772126 50704 mediawiki-math_1.12.0-2lenny9_hppa.deb Checksums-Sha256: d2b3ce684e5542760a4ddc50163aa57e54f2e5a3cb39630718f98731c9c47dbe 50704 mediawiki-math_1.12.0-2lenny9_hppa.deb Files: 30d807a138df2f9d4a66549312ce6993 50704 web optional mediawiki-math_1.12.0-2lenny9_hppa.deb -----BEGIN PGP SIGNATURE----- Version: GnuPG v1.4.9 (GNU/Linux) iQIcBAEBCAAGBQJO7nn3AAoJEHILVN/c8tMiHswP/iTBHbJggthCjvA2ilJEiytl wycUhYTBfcmyVQ1O3q31m5iejTAPr2tras+RMY/E8Y8WoEkMm7TrLp1ara53x8Xy yXp+svxjOSHXlhfzuD27q++5f/NL/UAkkDveGuX5uubyOkNb1e1ETMaSaf/cJljw G/IqTzZnC0LhkhNG3TA+N2cpihjMNq/uAxBz0hF2C6gQX3GoT0nP2fNmI/YNcsF7 3Vt08b2d/yKmhVkwSq1X7dGaFskc2tMBvnCQ4xpiFQNMh7dVR0ZCaYkwkLXo6dj7 rg5nWoaBFKw3S3GgIey9L0jJl0DIDObFXNTeXvsjAb5ktTi6l3XR2niEF2GpD23O oWeMhNbU0CzAnRoRJ1GUJVjcpDvkbfyyllIOcI5ODMMIKVqD76/wIOP9gnn7sB94 zAnjRv0DHblbxvo3Z3jQiMLaTpc2k3vLcUe8HHlJkM+KJ1A4VdOaouDKndBIRaZJ ozu1/QnGHQO1/HpkePq7WmX1qvW+4hQ9Gjbf05E1vMM5CJDs2v4e0tSr6+VzjU3I zHdZ0c5MibS1WwJ2KqnVRpTlP2moqSoQVZWIiZSg+ZJA/HqoFkoMxVvqQ11P6+Ea ML1Ia++xEkkREJBtLAKic7mr16/VMXyr3qWgSo1D+RMfM5Ro4xsNHBuY+mVnJc0+ BtVc6KpChvcwO65uoBY8 =fFGx -----END PGP SIGNATURE-----