mahara-packaging team mailing list archive
-
mahara-packaging team
-
Mailing list archive
-
Message #00063
[Bug 780917] Re: Major security updates for Mahara
Oneiric has 1.3.6-1, which is not vulnerable.
** Changed in: mahara (Ubuntu Oneiric)
Status: New => Fix Released
** Changed in: mahara (Ubuntu Lucid)
Status: New => Triaged
** Changed in: mahara (Ubuntu Lucid)
Importance: Undecided => High
** Changed in: mahara (Ubuntu Maverick)
Status: New => Triaged
** Changed in: mahara (Ubuntu Maverick)
Importance: Undecided => High
** Changed in: mahara (Ubuntu Natty)
Status: New => Triaged
** Changed in: mahara (Ubuntu Natty)
Importance: Undecided => High
--
You received this bug notification because you are a member of Mahara
Packaging, which is subscribed to mahara in Ubuntu.
https://bugs.launchpad.net/bugs/780917
Title:
Major security updates for Mahara
Status in “mahara” package in Ubuntu:
Fix Released
Status in “mahara” source package in Lucid:
Triaged
Status in “mahara” source package in Maverick:
Triaged
Status in “mahara” source package in Natty:
Triaged
Status in “mahara” source package in Oneiric:
Fix Released
Bug description:
Binary package hint: mahara
Here are packages to fix a number of very serious security issues in
all versions of Mahara:
* fixes to session key validation (CSRF)
* privilege escalations
* information disclosure in AJAX calls
* https to http downgrade
* sanitisation of HTML emails