-----BEGIN PGP SIGNED MESSAGE----- Hash: SHA1 Format: 1.8 Date: Fri, 04 Nov 2011 18:07:18 +0000 Source: moodle Binary: moodle Architecture: source all Version: 1.9.9.dfsg2-2.1+squeeze2 Distribution: stable-security Urgency: high Maintainer: Moodle Packaging Team Changed-By: Moritz Muehlenhoff Description: moodle - course management system for online learning Closes: 603255 614712 638935 Changes: moodle (1.9.9.dfsg2-2.1+squeeze2) stable-security; urgency=high . * Update prepared by Tomasz Muras: * Backporting security fixes from Moodle 1.9.13 and 1.9.14 - MSA-11-0026 Fields in user upload CSV not being escaped (MDL-28360) - MSA-11-0025 Group names in user upload CSV not being escaped (MDL-28197) - MSA-11-0024 Recaptcha images were being authenticated from an older server (MDL-27889) (closes: #638935) - MSA-11-0020 Continue links in error messages can lead offsite (MDL-27464) - MSA-11-0038 Database injection protection strengthened (MDL-29033) - MSA-11-0037 Course section editing injection vulnerability (MDL-28722) - MSA-11-0036 Messaging refresh vulnerability (MDL-29311) - MSA-11-0032 MNET SSL validation issue (MDL-29148) - MSA-11-0031 Forms API constant issue (MDL-23872) Make sure that smarty & yui symlinks are correct (closes: 603255,614712) Checksums-Sha1: 4b77f7d7bc05e32ea1c843511281544de951031d 1446 moodle_1.9.9.dfsg2-2.1+squeeze2.dsc 96579cd548a9436c2fdea25d890e6e64aff267e2 76113 moodle_1.9.9.dfsg2-2.1+squeeze2.debian.tar.gz 0c33ab068eca4fc32a850ab203822118b1b5383f 10018454 moodle_1.9.9.dfsg2-2.1+squeeze2_all.deb Checksums-Sha256: 97aea58662e7a0aeb7ff7580e5ca0a9f267ae4ed93d658c01aeb13710c072330 1446 moodle_1.9.9.dfsg2-2.1+squeeze2.dsc b182aa09e20f60dce53dbbf4e493a99c6ef5558347856d2ff454dc75193b7bc6 76113 moodle_1.9.9.dfsg2-2.1+squeeze2.debian.tar.gz a55063dec624b308512bfc070c5ab322a7c152beb93f72d599b759032f43038a 10018454 moodle_1.9.9.dfsg2-2.1+squeeze2_all.deb Files: 49ce72e4af8388476e9506163108df67 1446 web optional moodle_1.9.9.dfsg2-2.1+squeeze2.dsc 0494d98e2c81b6e29bc67a07f670677b 76113 web optional moodle_1.9.9.dfsg2-2.1+squeeze2.debian.tar.gz 29d7bffcb4930cccbb5c3fec4783604b 10018454 web optional moodle_1.9.9.dfsg2-2.1+squeeze2_all.deb -----BEGIN PGP SIGNATURE----- Version: GnuPG v1.4.11 (GNU/Linux) iEYEARECAAYFAk60KtcACgkQXm3vHE4uylq17ACeI3ZuN8bwzRZiE9oydCoYL+oI cccAoOxprh/h+gH0z88eXdhkAyiQLp7c =o43U -----END PGP SIGNATURE-----