*** This bug is a security vulnerability ***

Public security bug reported:

Binary package hint: movabletype-opensource

Several important fixes have gone into Debian since the last ubuntu
sync:

movabletype-opensource  (4.2.1-2) unstable; urgency=low

   * Fix SignIn widget by adapting JSON related code to new JSON.pm
     behaviour (closes: #498747). Thanks to Peter Gervai for the fix.

 -- Dominic Hargreaves <[EMAIL PROTECTED]>  Sat, 20 Sep 2008 23:50:53 +0100

movabletype-opensource (4.2.1-1) unstable; urgency=low

   * New upstream release (version 4.21)
     - fixes archive mapping bug (closes: #496776)
   * Change MTA dependencies to exim4 | mail-transport-agent. This is still
     not ideal but the best we can do pending a global fix (closes: #495858)

 -- Dominic Hargreaves <[EMAIL PROTECTED]>  Sun, 31 Aug 2008 22:01:39 +0100

movabletype-opensource (4.2-1) unstable; urgency=medium

   * New upstream final release
     - contains translation/doc updates and small bugfixes
   * Preserve urgency from previous release

 -- Dominic Hargreaves <[EMAIL PROTECTED]>  Wed, 13 Aug 2008 22:30:03 +0100

movabletype-opensource (4.2~rc5-1) unstable; urgency=medium

   * New upstream release candidate
   * Urgency medium as new release includes some preventative security fixes:
     
http://www.movabletype.org/2008/08/movable_type_42_rc5_and_security_updates.html

 -- Dominic Hargreaves <[EMAIL PROTECTED]>  Sat, 9 Aug 2008 15:13:40 +0100

including some security issues. I recommend that these changes be
considered for inclusion into your next release.

Security issues are CVE-2008-4079.

(Note: I'm not an Ubuntu user, just a concerned Debian developer :)

** Affects: movabletype-opensource (Ubuntu)
     Importance: Undecided
         Status: New

** Visibility changed to: Public

** Summary changed:

- conside syncing movabletype-opensource from Debian
+ consider syncing movabletype-opensource from Debian

-- 
consider syncing movabletype-opensource from Debian
https://bugs.launchpad.net/bugs/272889
You received this bug notification because you are a member of Ubuntu
Bugs, which is subscribed to Ubuntu.

-- 
ubuntu-bugs mailing list
ubuntu-bugs@lists.ubuntu.com
https://lists.ubuntu.com/mailman/listinfo/ubuntu-bugs

Reply via email to