-----BEGIN PGP SIGNED MESSAGE----- Hash: SHA256 Format: 1.8 Date: Fri, 13 Jul 2012 12:42:22 +0000 Source: mahara Binary: mahara mahara-apache2 mahara-mediaplayer Architecture: source all Version: 1.2.6-2+squeeze5 Distribution: stable-security Urgency: high Maintainer: Mahara Packaging Team <mahara-packaging@lists.launchpad.net> Changed-By: Melissa Draper <melissa@catalyst.net.nz> Description: mahara - Electronic portfolio, weblog, and resume builder mahara-apache2 - Electronic portfolio, weblog, and resume builder - apache2 config mahara-mediaplayer - Electronic portfolio, weblog, and resume builder - internal media Changes: mahara (1.2.6-2+squeeze5) stable-security; urgency=high . * SECURITY UPDATE: Fix multiple cross-site scripting vulnerabilities - Json-encode login form when injected by js - Sanitize links in links and resources menu - debian/patches/CVE-2012-2237-0001.patch: upstream patch - debian/patches/CVE-2012-2237-0002.patch: upstream patch Checksums-Sha1: fed5a581d5b4722a871cd6c15544ec8a844b6b75 1962 mahara_1.2.6-2+squeeze5.dsc 96180a4c911c6a0b5d27e5df3304a06c25ee596c 32313 mahara_1.2.6-2+squeeze5.debian.tar.gz 0c54613e7c1cf0cd2ecdc3bddfb27b7250dfe141 1637074 mahara_1.2.6-2+squeeze5_all.deb fde0842989c6d6bf4d8a2d1c29231d0b485a45e4 12834 mahara-apache2_1.2.6-2+squeeze5_all.deb cd38f205bbc085128e6386343abab46fb1eaf535 447926 mahara-mediaplayer_1.2.6-2+squeeze5_all.deb Checksums-Sha256: b34498d467514ecf5e6bfc57096f1e9ce1c095ff217840660975340edc4ce584 1962 mahara_1.2.6-2+squeeze5.dsc e8244513f2a60f1b1e873d8ab402f3fad71b50637341bf7768d371352a4c02c2 32313 mahara_1.2.6-2+squeeze5.debian.tar.gz 0fff9b9ae19f3d9704e467f9ed213d25fe7eacd01752bb64f17cc5d76397c396 1637074 mahara_1.2.6-2+squeeze5_all.deb fb49a250a2d980df38285e425ab4db1f8a2126b3445c793dadcb05f224617ede 12834 mahara-apache2_1.2.6-2+squeeze5_all.deb 5f4be4499a1f89553f4b20b744a5253052c925f339ac64fcfe609ad7654baad0 447926 mahara-mediaplayer_1.2.6-2+squeeze5_all.deb Files: 0fb46310a5d970f839ff4c4720b7b8fa 1962 web optional mahara_1.2.6-2+squeeze5.dsc 4661aef903c3c708f7255031a5ad242c 32313 web optional mahara_1.2.6-2+squeeze5.debian.tar.gz 15c5089a2a0392d4ae9f9519a58f1635 1637074 web optional mahara_1.2.6-2+squeeze5_all.deb ac0d3451bd240b954ac16f33a8d3c5f9 12834 web optional mahara-apache2_1.2.6-2+squeeze5_all.deb 9b20adde2b6b22056bc1e31faf4d14d4 447926 contrib/web optional mahara-mediaplayer_1.2.6-2+squeeze5_all.deb -----BEGIN PGP SIGNATURE----- Version: GnuPG v1.4.10 (GNU/Linux) iQIcBAEBCAAGBQJQKOTbAAoJEBYoHy4AfJjRcM4P/0gTPAaLXF40n9ZO2U+6PkN2 LTTQMqyF4GB4KsW09n+E2BHeseMJE0Prh5WNO80cx+tPkMcobL/m1iSkGvBBtQYb MdRRKRbJedWjHsavASjPLsxx8KKsRgQLdDl/cit7KijjDZW1KFtoL/9E5lyOsmJp dP7QKQKd4ETShR+FmfFVRalC5MoTkZnqehhCLY54yjxkB5/eaC/vrNYuMMO2j8ZL aF0CdJuDM0Vc+trd3DoAmhLoz7K67qHnU8cl0QhSiIEGbKECgZQWmr+rIAII/bVM Q56TUZ37HO5htsVb3cmAg0AYzBed1KWl0UXm8Q20NpB+kW8tUwclj6IdGnwSu3uD PIF7SSQobe+ENHcNhS2tvSURpSBUBdUTMxILdOQoHlFLNnbH/3P6Q8LG4lz1CX/H 67gunn/8dpz0njetMEDvuw4SNnkH0zycqh3X51klRdkdB08rHZsPjXL2UMLRNuu+ iAIz/NbNL0NebJYlZ1P3y0s9Wz55c2Rz7tV3WoxbK5e0Nj9JPRE3l8zsuMMl3PdE 8XGzufX5QF0rjvZZtjOchOKR8eAZ/LJsTUFEy3ZMqAY0sFxW0IUPRO/GBadwRcWH O3r9rxZGJGmblAnzKMCHZT6JIq4/pRPdzxG3lLhE8dbcKfnAbxs0ZyKkM98Gkwq+ enLUL4YrZfzPMW4Vc/xi =kU1d -----END PGP SIGNATURE-----