[ubuntu/lucid] moin 1.9.2-2ubuntu2 (Accepted)

Jamie Strandboge jamie at ubuntu.com
Tue Mar 30 22:35:24 BST 2010


moin (1.9.2-2ubuntu2) lucid; urgency=low

  * Debian declares python-werkzeug and python-parsedatetime as Depends and
    python-xappy as Recommends, however these packages are in universe,
    which breaks Ubuntu policy (section 2.2.1). Until these packages can be
    added to main, use the embedded copies in moin.
    - debian/patches/ubuntu_use_embedded_for_main.patch: update setup.py
    - debian/rules: update CDBS_DEPENDS and CDBS_RECOMMENDS for the above
  * SECURITY UPDATE: fix XSS in Despam action
    - debian/patches/CVE-2010-0828.patch: use wikiutil.escape() in
      revert_pages()
    - CVE-2010-0828

Date: Tue, 30 Mar 2010 15:09:54 -0500
Changed-By: Jamie Strandboge <jamie at ubuntu.com>
Maintainer: Ubuntu Core Developers <ubuntu-devel-discuss at lists.ubuntu.com>
https://launchpad.net/ubuntu/lucid/+source/moin/1.9.2-2ubuntu2
-------------- next part --------------
-----BEGIN PGP SIGNED MESSAGE-----
Hash: SHA1

Format: 1.8
Date: Tue, 30 Mar 2010 15:09:54 -0500
Source: moin
Binary: python-moinmoin
Architecture: source
Version: 1.9.2-2ubuntu2
Distribution: lucid
Urgency: low
Maintainer: Ubuntu Core Developers <ubuntu-devel-discuss at lists.ubuntu.com>
Changed-By: Jamie Strandboge <jamie at ubuntu.com>
Description: 
 python-moinmoin - Python clone of WikiWiki - library
Changes: 
 moin (1.9.2-2ubuntu2) lucid; urgency=low
 .
   * Debian declares python-werkzeug and python-parsedatetime as Depends and
     python-xappy as Recommends, however these packages are in universe,
     which breaks Ubuntu policy (section 2.2.1). Until these packages can be
     added to main, use the embedded copies in moin.
     - debian/patches/ubuntu_use_embedded_for_main.patch: update setup.py
     - debian/rules: update CDBS_DEPENDS and CDBS_RECOMMENDS for the above
   * SECURITY UPDATE: fix XSS in Despam action
     - debian/patches/CVE-2010-0828.patch: use wikiutil.escape() in
       revert_pages()
     - CVE-2010-0828
Checksums-Sha1: 
 345d1c74c9cc946e41767be4090101f9cf83160d 1289 moin_1.9.2-2ubuntu2.dsc
 bfadaa3e0ca73cd71457ea5f1938b34222705802 116418 moin_1.9.2-2ubuntu2.debian.tar.gz
Checksums-Sha256: 
 b36448cff96aaec8d4e04062342d7643279624e671a8e136bc9ff9d557090e18 1289 moin_1.9.2-2ubuntu2.dsc
 6c3fa5be1a26dec72a86ea4d6c02e590792ef8a10b60f2efad6e04ea3a6663fd 116418 moin_1.9.2-2ubuntu2.debian.tar.gz
Files: 
 bad1869b1de2a35a0763e4b0480ea182 1289 net optional moin_1.9.2-2ubuntu2.dsc
 4a5ceb8043d9929b76f0b19ce1022476 116418 net optional moin_1.9.2-2ubuntu2.debian.tar.gz
Original-Maintainer: Jonas Smedegaard <dr at jones.dk>

-----BEGIN PGP SIGNATURE-----
Version: GnuPG v1.4.10 (GNU/Linux)

iEYEARECAAYFAkuybVgACgkQW0JvuRdL8BpBaACfSU9LdGYG7nPg0xLDr25M2eIQ
k28AmQH3PElHCCUmv/TwFzMmGFMWTe5Z
=qBbg
-----END PGP SIGNATURE-----


More information about the Lucid-changes mailing list