Accepted mediawiki 1:1.12.0-2lenny5 (source all amd64)
-----BEGIN PGP SIGNED MESSAGE-----
Hash: SHA1
Format: 1.8
Date: Fri, 16 Apr 2010 14:59:06 -0500
Source: mediawiki
Binary: mediawiki mediawiki-math
Architecture: source all amd64
Version: 1:1.12.0-2lenny5
Distribution: stable-security
Urgency: high
Maintainer: Mediawiki Maintenance Team <pkg-mediawiki-devel@lists.alioth.debian.org>
Changed-By: Romain Beauxis <toots@rastageeks.org>
Description:
mediawiki - website engine for collaborative work
mediawiki-math - math rendering plugin for MediaWiki
Changes:
mediawiki (1:1.12.0-2lenny5) stable-security; urgency=high
.
* Security upload. Fixes the following issue (CVE-2010-1150):
"MediaWiki was found to be vulnerable to login CSRF. An attacker who
controls a user account on the target wiki can force the victim to log
in as the attacker, via a script on an external website. If the wiki is
configured to allow user scripts, say with "$wgAllowUserJs = true" in
LocalSettings.php, then the attacker can proceed to mount a
phishing-style attack against the victim to obtain their password.
Checksums-Sha1:
c39400d3509e7968779e02c843896f481c9ec701 1549 mediawiki_1.12.0-2lenny5.dsc
621f46a5cb9abd3b8df234241bed007f418e085d 64013 mediawiki_1.12.0-2lenny5.diff.gz
d1f69049678d397d23aeef443552bfe22bd672d4 7232192 mediawiki_1.12.0-2lenny5_all.deb
bafbaab7d516bec0ac5cfa762ef4c9dec6ec873a 157208 mediawiki-math_1.12.0-2lenny5_amd64.deb
Checksums-Sha256:
44c035047342280073bff86c1b5a54ed5bf5060eba0c2169b0b2244b5c3d8f1d 1549 mediawiki_1.12.0-2lenny5.dsc
364cc1f7489cd21b2200c322b919ff75e05c9b94bcaeaa5998a2a85a1deb3898 64013 mediawiki_1.12.0-2lenny5.diff.gz
d75dd46c851fa5b839053fa37ab83d4db28f5f4988a9d5138ef22633cbc287c5 7232192 mediawiki_1.12.0-2lenny5_all.deb
ecf6edce9a66c580900dcca6a805b44c8f6b14f69cdc19fd9b54887a561ce9b2 157208 mediawiki-math_1.12.0-2lenny5_amd64.deb
Files:
95beff777c2aabfc1c27ee705d6e962d 1549 web optional mediawiki_1.12.0-2lenny5.dsc
4bda93a5b7657c02615abb552a52656f 64013 web optional mediawiki_1.12.0-2lenny5.diff.gz
376a7e8a9d5ef623d9f742c46b6731d2 7232192 web optional mediawiki_1.12.0-2lenny5_all.deb
be32615f5aa6e9eb8c7cb9856190667e 157208 web optional mediawiki-math_1.12.0-2lenny5_amd64.deb
-----BEGIN PGP SIGNATURE-----
Version: GnuPG v1.4.10 (GNU/Linux)
iQEcBAEBAgAGBQJLyjS4AAoJEAC5aaocqV0ZX10H/3pA584s53dsThVXOxCQrAdg
tqo2Ar9OFeAm1ShRX4hHmUv4JM6aqkSfiHb1w3avIyVLwk6UxBQ2L5zHPQwyBS2E
cp6m1BE7cFGN+WJcNsnZrEB7idNO7hofJX/XJMQ2mqob33SYxB2PDvZbAHYnsVq5
kfxfDjEoZNeaFV2uJm4HrIfS/eMoPYo9HeK/pm9g9IihG16UIpPAMxUJGqbsyaZQ
6qGuLio5nogTIQoy6QirldlYkCTpQo2583ezYN1psL/GbzdhF0UzCLNnjbn3Y5q2
1006Qa8M7rKJASzX/zvMCauh0jUx2tZI5ZJYPuMu/UE4dOVbw+csyinu8mOYWtQ=
=j7QF
-----END PGP SIGNATURE-----
Accepted:
mediawiki-math_1.12.0-2lenny5_amd64.deb
to main/m/mediawiki/mediawiki-math_1.12.0-2lenny5_amd64.deb
mediawiki_1.12.0-2lenny5.diff.gz
to main/m/mediawiki/mediawiki_1.12.0-2lenny5.diff.gz
mediawiki_1.12.0-2lenny5.dsc
to main/m/mediawiki/mediawiki_1.12.0-2lenny5.dsc
mediawiki_1.12.0-2lenny5_all.deb
to main/m/mediawiki/mediawiki_1.12.0-2lenny5_all.deb