-----BEGIN PGP SIGNED MESSAGE----- Hash: SHA1 Format: 1.8 Date: Thu, 11 Mar 2010 23:09:05 +0100 Source: moin Binary: python-moinmoin Architecture: source all Version: 1.7.1-3+lenny3 Distribution: stable-security Urgency: high Maintainer: Jonas Smedegaard <dr@jones.dk> Changed-By: Giuseppe Iuculano <iuculano@debian.org> Description: python-moinmoin - Python clone of WikiWiki - library Closes: 569975 Changes: moin (1.7.1-3+lenny3) stable-security; urgency=high . * Non-maintainer upload by the Security Team. * Fixed CVE-2010-0668: Multiple security issue related to configurations that have a non-empty superuser list, the xmlrpc action enabled, the SyncPages action enabled, or OpenID configured. (Closes: #569975) * Fixed CVE-2010-0669: MoinMoin does not properly sanitize user profiles * Fixed CVE-2010-0717: The default configuration of cfg.packagepages_actions_excluded does not prevent unsafe package actions * hierarchical ACL security fix: error when processing hierarchical ACLs, which can be exploited to access restricted sub-pages. Checksums-Sha1: b38a7db1a28783271eb8aab3b87b149396340ada 1259 moin_1.7.1-3+lenny3.dsc e8a9216e5e3a479ec724df147928ef9bed72c494 89391 moin_1.7.1-3+lenny3.diff.gz 4684e8e06a0387caddc30cfb820f71946f44cebb 4510584 python-moinmoin_1.7.1-3+lenny3_all.deb Checksums-Sha256: adf6f2e99c531ec0c775b09da396db36c871a14e7b9a480ff8a7f6ff1d2342d1 1259 moin_1.7.1-3+lenny3.dsc 0bbbe860209eda16de306bd9cd062cb4f758cf336410680769efcbf872caca2b 89391 moin_1.7.1-3+lenny3.diff.gz 4234eb2594a0a4b6ee5f30a8e374d92740c2ae5f4f13a50e602c2e5b59c6a8f2 4510584 python-moinmoin_1.7.1-3+lenny3_all.deb Files: 66683a3699687a13f1d814e24bc46dbd 1259 net optional moin_1.7.1-3+lenny3.dsc 38256114fbb76fcb388ce5ca148acbac 89391 net optional moin_1.7.1-3+lenny3.diff.gz a9440eb4eccc639f5dc1c7e2f27a9857 4510584 python optional python-moinmoin_1.7.1-3+lenny3_all.deb -----BEGIN PGP SIGNATURE----- Version: GnuPG v1.4.10 (GNU/Linux) iEYEARECAAYFAkuaAbMACgkQNxpp46476ap5TgCghZvI1nIomv9SBsl6yzBkRC2p EmcAoIERWqAP94z57o3tg2ZpJ2bQ7Hv3 =xOG/ -----END PGP SIGNATURE----- Accepted: moin_1.7.1-3+lenny3.diff.gz to main/m/moin/moin_1.7.1-3+lenny3.diff.gz moin_1.7.1-3+lenny3.dsc to main/m/moin/moin_1.7.1-3+lenny3.dsc python-moinmoin_1.7.1-3+lenny3_all.deb to main/m/moin/python-moinmoin_1.7.1-3+lenny3_all.deb