Name Status Last Modified Last Commit
lp:debian/stretch/dokuwiki 1 Development 2015-05-26 04:28:08 UTC
42. * New upstream hotfix releases: + ...

Author: Tanguy Ortolo
Revision Date: 2015-03-22 17:00:41 UTC

* New upstream hotfix releases:
   + prevent XSS attack via SWF uploads. (CVE-2014-9253) (Closes: #773429)
   + fix privilege escalation in RPC API (CVE-2015-2172) (Closes: #779547)
   + fix an XSS vulnerability in the user manager (Closes: #780817)

lp:debian/jessie/dokuwiki 1 Development 2015-03-22 17:40:22 UTC
38. * debian/patches: security fix, from ...

Author: Tanguy Ortolo
Revision Date: 2015-03-22 17:40:22 UTC

* debian/patches: security fix, from upstream hotfix release
   + cve-2015-2172_check_permissions_in_rpc.patch: check permissions in the
     ACL plugin's RPC API to avoid a privilege escalation. (CVE-2015-2172)
     (Closes: #779547)

lp:debian/dokuwiki bug 1 Development 2015-03-22 17:00:41 UTC
42. * New upstream hotfix releases: + ...

Author: Tanguy Ortolo
Revision Date: 2015-03-22 17:00:41 UTC

* New upstream hotfix releases:
   + prevent XSS attack via SWF uploads. (CVE-2014-9253) (Closes: #773429)
   + fix privilege escalation in RPC API (CVE-2015-2172) (Closes: #779547)
   + fix an XSS vulnerability in the user manager (Closes: #780817)

lp:debian/wheezy/dokuwiki 1 Development 2014-10-29 09:23:25 UTC
30. * debian/patches: + fix_ldap_auth_...

Author: Tanguy Ortolo
Revision Date: 2014-10-29 09:23:25 UTC

* debian/patches:
   + fix_ldap_auth_bypass_CVE-2014-8763.diff: fix an authentication bypass
     flaw when using Active Directory for LDAP
     authentication. (CVE-2014-8763)
   + fix_media_acl_bypass_CVE-2014-8762.diff: fix a media ACL bypass flaw.
     (CVE-2014-8761, CVE-2014-8762)

lp:debian/experimental/dokuwiki 1 Development 2014-08-25 14:50:16 UTC
24. * New upstream hotfix release. * debi...

Author: Tanguy Ortolo
Revision Date: 2014-08-25 14:50:16 UTC

* New upstream hotfix release.
* debian/copyright: correct syntax to exclude two non-free files
  (it is Files-Excluded, not Exclude).
* debian/README.Debian:
   - correct a dead HTTP link. (Closes: #752676)
   - document the new default password for insane debconf configurations.
* debian/watch: add a . (dot) before the patch level in the Debian version
  number (this is because 0.0.20140505a+dfsg-1 < 0.0.20140505+dfsg-1!).
* debian/dokuwiki.cron.daily: add a cron job to do cleanup and, if
  configured, spam blacklist update. (Closes: #756050)
* debian/dokuwiki.default: add a configuration file for the cleanup and spam
  blacklist update cron job.
* debian/control: add wget to Recommends as it would be needed for spam
  blacklist update.
* debian/config: change priority of webservers to configure (now medium) and
  add a default admin password for insane installations where debconf is
  configured to ignore even high priority questions)

lp:debian/lenny/dokuwiki 2 Mature 2011-10-06 21:03:07 UTC
8. debian/patches/rss_security.diff: avo...

Author: Tanguy Ortolo
Revision Date: 2011-10-06 21:03:07 UTC

debian/patches/rss_security.diff: avoid calling an undefined function.
(Closes: #644145)

lp:debian/squeeze/dokuwiki bug 1 Development 2011-06-29 01:46:43 UTC
19. debian/patches/rss_security.diff: Bac...

Author: Tanguy Ortolo
Revision Date: 2011-06-29 01:46:43 UTC

debian/patches/rss_security.diff: Backport an upstream security fix for
an XSS vulnerability in the RSS embedding mechanism. (CERTA-2011-AVI-366)

17 of 7 results