-----BEGIN PGP SIGNED MESSAGE----- Hash: SHA1 Format: 1.8 Date: Sun, 18 Dec 2011 23:19:40 +0000 Source: mediawiki Binary: mediawiki mediawiki-math Architecture: arm Version: 1:1.12.0-2lenny9 Distribution: lenny-security Urgency: low Maintainer: arm Build Daemon (cats) Changed-By: Jonathan Wiltshire Description: mediawiki - website engine for collaborative work mediawiki-math - math rendering plugin for MediaWiki Closes: 650434 Changes: mediawiki (1:1.12.0-2lenny9) oldstable-security; urgency=low . * Security fixes from upstream (Closes: #650434): CVE-2011-4360 - page titles on private wikis could be exposed bypassing different page ids to index.php CVE-2011-4361 - action=ajax requests were dispatched to the relevant function without any read permission checks being done CVE-2011-1578 - XSS for IE <= 6 CVE-2011-1579 - CSS validation error in wikitext parser CVE-2011-1580 - access control checks on transwiki import feature CVE-2011-1587 - fix incomplete patch for CVE-2011-1578 Checksums-Sha1: d429783d8ec4e3a4f6492a34e091a307a928b7c4 50706 mediawiki-math_1.12.0-2lenny9_arm.deb Checksums-Sha256: 927c50328b87a10eacf85d6f3ad6d3571720bb3d1eaca87d93e10f4ac8351827 50706 mediawiki-math_1.12.0-2lenny9_arm.deb Files: 461cb41b26172a37d9d0bad629cf329c 50706 web optional mediawiki-math_1.12.0-2lenny9_arm.deb -----BEGIN PGP SIGNATURE----- Version: GnuPG v1.4.11 (GNU/Linux) iEYEARECAAYFAk7vkAEACgkQXm3vHE4uylrSSQCgiTfmTrNUrJOT/zED+kMaTuYn A3IAoJ6G8AEZXuaMzT0eDXTms+UQhJq7 =SpGT -----END PGP SIGNATURE-----