-----BEGIN PGP SIGNED MESSAGE----- Hash: SHA256 Format: 1.8 Date: Mon, 19 Sep 2016 11:31:50 +0200 Source: moodle Binary: moodle Architecture: source all Version: 2.7.16+dfsg-1 Distribution: unstable Urgency: high Maintainer: Moodle Packaging Team <pkg-moodle-maintainers@lists.alioth.debian.org> Changed-By: Joost van Baal-Ilić <joostvb@debian.org> Description: moodle - course management system for online learning Changes: moodle (2.7.16+dfsg-1) unstable; urgency=high . * New upstream security release, released 12 Sept 2016. Security issues fixed: - MSA-16-0022 (CVE-2016-7038) Web service tokens should be invalidated when the user password is changed or forced to be changed. Reported by Juan Leyva. MDL-49026 See https://docs.moodle.org/dev/Moodle_2.7.16_release_notes for more details. Note that the upstream 2.7 branch is supported for security fixes only until May 2017 (LTS). For the last year, upstream has shipped a security release every 2nd monday of each odd month; therefore we expect next releases at Nov 14, 2016 and Jan 9, 2017. Checksums-Sha1: ec18c8e5c5b154dcd398cfc649ecc83d32a8384a 1642 moodle_2.7.16+dfsg-1.dsc 867e591f05fad961b7f2f2c905ad6ffa39864686 23424380 moodle_2.7.16+dfsg.orig.tar.xz 7ea288331e63b20cdd407a7b420818accc04b7b1 72216024 moodle_2.7.16+dfsg-1.debian.tar.xz c30c2b18288cd398fc74186ca99a8a42b85e7f7a 15416638 moodle_2.7.16+dfsg-1_all.deb Checksums-Sha256: 565e9a97d23f4ba8e918d1920eb84b4498ce5993a861127efd2fa0cac12aa655 1642 moodle_2.7.16+dfsg-1.dsc 76d60ab01b427021341426e39251e079e8b5029e6dd3bd79fced98ded57eb16c 23424380 moodle_2.7.16+dfsg.orig.tar.xz 89660071fa01be349145d1add5723d4607ef4991a4636a8ef227f0df9411cd82 72216024 moodle_2.7.16+dfsg-1.debian.tar.xz b188f7186db7de3e77710c700806fbd8649dddb36dbd3943e6736c4698f10441 15416638 moodle_2.7.16+dfsg-1_all.deb Files: 8b6af380089cb1d281021f3de5737b13 1642 web optional moodle_2.7.16+dfsg-1.dsc 0a5f509d29f0952ee16111818cdf866d 23424380 web optional moodle_2.7.16+dfsg.orig.tar.xz c030119758239e7c617c7f0f5969d62c 72216024 web optional moodle_2.7.16+dfsg-1.debian.tar.xz 0a78db75a352c7fa1bd981ab079cdc3f 15416638 web optional moodle_2.7.16+dfsg-1_all.deb -----BEGIN PGP SIGNATURE----- iQEcBAEBCAAGBQJX38LvAAoJEDNRenKl5rDIgvoIAJWGr++aE4xQFDBn7195W2kR PpDw9VTPdt+O1Hm4U3UsKZry2OsFEV0BEmuvAZ+mS9hn7mokLAhVv7LZBAAmCdz/ HjoFY/+TvStNSDzIRDEWZNXUGAg1MxVDXVUTFDgWRMvExCatlSsb5786+OkW9+7d LKacVZhqPp6iG7dCueGC5dRy2T7fB+ePqKgePpTd1xCR0t8pCXr/6fSq5pqIgsl8 mos5QEmkcAfLPbnrYFN1wSTyONCkhKXcfG/dqpB4vk/TG9cBwRV0FPQmy77gxt8K fJJ/CcH1SkwWmBTWyBfFr3q+z74GoxL5MZksltpi2M6zSKp79VEmQGSd/CDrlv4= =XcXu -----END PGP SIGNATURE-----