-----BEGIN PGP SIGNED MESSAGE----- Hash: SHA1 Format: 1.8 Date: Sun, 18 Dec 2011 23:17:47 +0000 Source: mediawiki Binary: mediawiki mediawiki-math Architecture: kfreebsd-i386 Version: 1:1.15.5-2squeeze2 Distribution: squeeze-security Urgency: low Maintainer: kfreebsd-i386 Build Daemon (field) Changed-By: Jonathan Wiltshire Description: mediawiki - website engine for collaborative work mediawiki-math - math rendering plugin for MediaWiki Closes: 650434 Changes: mediawiki (1:1.15.5-2squeeze2) stable-security; urgency=low . * Security fixes from upstream (Closes: #650434): CVE-2011-4360 - page titles on private wikis could be exposed bypassing different page ids to index.php CVE-2011-4361 - action=ajax requests were dispatched to the relevant function without any read permission checks being done CVE-2011-1578 - XSS for IE <= 6 CVE-2011-1579 - CSS validation error in wikitext parser CVE-2011-1580 - access control checks on transwiki import feature CVE-2011-1587 - fix incomplete patch for CVE-2011-1578 Checksums-Sha1: 50b5bd3bfced47bea80c47db7da2083deea5cd12 282168 mediawiki-math_1.15.5-2squeeze2_kfreebsd-i386.deb Checksums-Sha256: c61f05f7ae3de58a766a479daf1b59f1fe8509108b93c9b0ab5d828474b78133 282168 mediawiki-math_1.15.5-2squeeze2_kfreebsd-i386.deb Files: 59ae4ec2e34c6841b56d9da66c1e74f5 282168 web optional mediawiki-math_1.15.5-2squeeze2_kfreebsd-i386.deb -----BEGIN PGP SIGNATURE----- Version: GnuPG v1.4.10 (GNU/kFreeBSD) iQIcBAEBAgAGBQJO7+GLAAoJEEzv3ERlujMca14P/3ef21yhGsrnKuN3PezhS0PC o2jMI0pfaAJIY1uTzfR4WJmRQp/GbSWDtyXhY9VDz21m0HAljM4z2Lw95Q07or2o LKPrxoSFiFWo7da3FXmicKKSu0+5y7Co3xrxAzbQ+xI3vD+h04dU6tY45pt/GKee dd9XJOEfrJzvuE0SrxdXnz7nCzPxYV1+LTa68d6XF2hSQ1jR69PveYgmtmgG7dIx QbK3vyLNu4xOdRDwiOOvjjwyupAXzavY53rn77VrSFMD+vbAo+Kl50MA8O6MbWlI GJSE4bAzzGku0YYixBsOZ/PUyfnaAODpEeCd93oYBBSKit7d6KWPBWVnwLMzxABx hdhr+LhQochsaqPWAxOPrNZkV3/N782V46pELI8mjpyksL4Kvkd9RojJwLvZIC4E ZaQmHAXiGwa4sgeVR4Z3gg8gSXAq3y2igaSv6M7GR8et/1Zhfzk5MeBtaLhMpXZJ +hKbK1xN9B8mXgpKzBOM7uRXXKtASksuLxToO6lQi1tTcpltAdCt/xjxON3TudAr Nn8hy1GpZUqe9CAyWVVlJoWrKFU4lJaglRlIw8Czu3oj9If+2looQQIjgpJFhCsQ Vfvx3fVQblm42NAIZpbV2DR+viQkvwJtRn4+LL+tHvmj9ECo8fCVTlkrhTwqxjTe yeMy2MlreUrzCuJi1RH9 =Bu6i -----END PGP SIGNATURE-----