-----BEGIN PGP SIGNED MESSAGE----- Hash: SHA256 Format: 1.8 Date: Sun, 18 Dec 2011 23:19:40 +0000 Source: mediawiki Binary: mediawiki mediawiki-math Architecture: armel Version: 1:1.12.0-2lenny9 Distribution: lenny-security Urgency: low Maintainer: armel Build Daemon (alwyn) Changed-By: Jonathan Wiltshire Description: mediawiki - website engine for collaborative work mediawiki-math - math rendering plugin for MediaWiki Closes: 650434 Changes: mediawiki (1:1.12.0-2lenny9) oldstable-security; urgency=low . * Security fixes from upstream (Closes: #650434): CVE-2011-4360 - page titles on private wikis could be exposed bypassing different page ids to index.php CVE-2011-4361 - action=ajax requests were dispatched to the relevant function without any read permission checks being done CVE-2011-1578 - XSS for IE <= 6 CVE-2011-1579 - CSS validation error in wikitext parser CVE-2011-1580 - access control checks on transwiki import feature CVE-2011-1587 - fix incomplete patch for CVE-2011-1578 Checksums-Sha1: af0ad33f3ceab166bb9f1980f5f3a01de6509c18 50708 mediawiki-math_1.12.0-2lenny9_armel.deb Checksums-Sha256: 1918b58e9ceed037fb424561ebabfbe4af0295cc8345ceea6eb06b8a6b6d017a 50708 mediawiki-math_1.12.0-2lenny9_armel.deb Files: 676139a1456c0288f58b19c47533ea4c 50708 web optional mediawiki-math_1.12.0-2lenny9_armel.deb -----BEGIN PGP SIGNATURE----- Version: GnuPG v1.4.10 (GNU/Linux) iQIcBAEBCAAGBQJO7noPAAoJEBRVXZHoMsNVzM0P/3KPIjPb1ePr0DBozYXTQ6lh 9X1R7C7qTvH1PihROTq8weVzZauDmeID9WnbQfDDzbYbS1DMkppM/vZHaPCJMHzp 31j5Ukj8kaJ2I4zBHTj819+Kz27k0DyH3r7F3e2h3Fca6XegJDMLiPTtQnxKVjF9 ZXeZo3aDuyUnovVm73q9/VGtNflVudxROl2Z0nqd54ldBhM/TDQYRTOlnF1MDvVt cQovs9QGohUayw7JtD6Uxa+82BPp4sTeKBf/oAEoR4bS3DD0DmtOyN8qToAbe5b9 2mU6kQFJQc5GvwOHdYPgKnQ95KZ1YoX9pdZCJFEvixAJ5SfOHDNeJu/awbRWHU9q ydY2lqIekYHFS8FWrx4IdRR2Oqy5mGXkpDAwPiy4A2U8S4lCIeiqo4iKcDuHSjhY iEi/SKouKvQb5nlUgrFZ0GN2gnso/siTpvFv1b2EDMZ0CbhxT142jfg4dOQBkz2w X609mctonwL2EMSe+Fwc4TSa0aOCs7kU2EcwO2cvePEEhMX2v/RRNAFao2XJm5yo SxGwckas6LjGtagdy3Ewv7s2esBvge8jAwrBzkCxtCCdHMX0ldmbtv24ZloBIZqB nWE2/oa2Fx6wykxDz6IRu025t0rhu7UDC2qdjYSxrdXIjm0OxvqUQbTHkjqvhAHG nMkOIHohUMZSHddbrlVv =SGE+ -----END PGP SIGNATURE-----