-----BEGIN PGP SIGNED MESSAGE----- Hash: SHA1 Format: 1.8 Date: Thu, 25 Nov 2010 13:48:45 +0100 Source: openacs Binary: openacs Architecture: source all Version: 5.5.1+dfsg-2 Distribution: unstable Urgency: high Maintainer: Hector Romojaro <hromojaro@dia.uned.es> Changed-By: Hector Romojaro <hromojaro@dia.uned.es> Description: openacs - toolkit for building community-oriented web applications Closes: 598364 599004 599606 599607 Changes: openacs (5.5.1+dfsg-2) unstable; urgency=high . * Fixed severe vulnerability in the api-browser: it was possible to pass to the query parameter "path" a relative path, which might contain path traversals like ../../.. . With these all files with read permissions can be delivered via the server. Applied Patch: http://fisheye.openacs.org/changelog/OpenACS/?cs=oacs-5-5:gustafn:20101125091953 * Updated translations: - Vietnamese. Closes: #599607 - Czech. Closes: #599606 - Danish. Closes: #599004 - Japanese. Closes: #598364 Checksums-Sha1: d409552717860d2bd18f9b5246180e011cf7e8e1 1249 openacs_5.5.1+dfsg-2.dsc 50486f2353defca124131764648c8d161326d56d 48093 openacs_5.5.1+dfsg-2.diff.gz f2e67d021960eb2666897b66c8853af0ccb30880 10064052 openacs_5.5.1+dfsg-2_all.deb Checksums-Sha256: 83a9765604ceb3973b97144c2207423c5efc7299370f2f8244cf38e7bec92f2a 1249 openacs_5.5.1+dfsg-2.dsc 6993acc9cbe516c4f3a4df6ab053fb6d5519d93b1a62a0a91a4af70c6793ac36 48093 openacs_5.5.1+dfsg-2.diff.gz 7b9cd33c3aeb0dde40328988634cf3e1a1e9862f308116d2b92c4ab17f533b2e 10064052 openacs_5.5.1+dfsg-2_all.deb Files: 17077e899cca95ab9f008b22aca9201d 1249 web optional openacs_5.5.1+dfsg-2.dsc 9beddf7df7a522951b109276d20e87c1 48093 web optional openacs_5.5.1+dfsg-2.diff.gz 7b0e066d287b325d13921ff4cdecfc00 10064052 web optional openacs_5.5.1+dfsg-2_all.deb -----BEGIN PGP SIGNATURE----- Version: GnuPG v1.4.10 (GNU/Linux) iEYEARECAAYFAkzyMBcACgkQpFNRmenyx0dZTACcDzku2phKUpqH8ybLY93Z9xep MeAAnilaXl6LDUS0iSzXT+4xOvScxp9I =qHFU -----END PGP SIGNATURE----- Accepted: openacs_5.5.1+dfsg-2.diff.gz to main/o/openacs/openacs_5.5.1+dfsg-2.diff.gz openacs_5.5.1+dfsg-2.dsc to main/o/openacs/openacs_5.5.1+dfsg-2.dsc openacs_5.5.1+dfsg-2_all.deb to main/o/openacs/openacs_5.5.1+dfsg-2_all.deb