consider syncing movabletype-opensource from Debian

Bug #272889 reported by Dominic Hargreaves
258
Affects Status Importance Assigned to Milestone
movabletype-opensource (Ubuntu)
Fix Released
Low
Unassigned
Intrepid
Invalid
Low
Unassigned
Jaunty
Fix Released
Low
Unassigned

Bug Description

Binary package hint: movabletype-opensource

Several important fixes have gone into Debian since the last ubuntu sync:

movabletype-opensource (4.2.1-2) unstable; urgency=low

   * Fix SignIn widget by adapting JSON related code to new JSON.pm
     behaviour (closes: #498747). Thanks to Peter Gervai for the fix.

 -- Dominic Hargreaves <email address hidden> Sat, 20 Sep 2008 23:50:53 +0100

movabletype-opensource (4.2.1-1) unstable; urgency=low

   * New upstream release (version 4.21)
     - fixes archive mapping bug (closes: #496776)
   * Change MTA dependencies to exim4 | mail-transport-agent. This is still
     not ideal but the best we can do pending a global fix (closes: #495858)

 -- Dominic Hargreaves <email address hidden> Sun, 31 Aug 2008 22:01:39 +0100

movabletype-opensource (4.2-1) unstable; urgency=medium

   * New upstream final release
     - contains translation/doc updates and small bugfixes
   * Preserve urgency from previous release

 -- Dominic Hargreaves <email address hidden> Wed, 13 Aug 2008 22:30:03 +0100

movabletype-opensource (4.2~rc5-1) unstable; urgency=medium

   * New upstream release candidate
   * Urgency medium as new release includes some preventative security fixes:
     http://www.movabletype.org/2008/08/movable_type_42_rc5_and_security_updates.html

 -- Dominic Hargreaves <email address hidden> Sat, 9 Aug 2008 15:13:40 +0100

including some security issues. I recommend that these changes be considered for inclusion into your next release.

Security issues are CVE-2008-4079.

(Note: I'm not an Ubuntu user, just a concerned Debian developer :)

Changed in movabletype-opensource:
status: New → Confirmed
importance: Undecided → Low
status: New → Fix Released
importance: Undecided → Low
Revision history for this message
Alex Valavanis (valavanisalex) wrote :

Intrepid Ibex reached end-of-life on 30 April 2010 so I am closing the
report. The bug has been fixed in newer releases of Ubuntu.

Changed in movabletype-opensource (Ubuntu Intrepid):
status: Confirmed → Invalid
To post a comment you must log in.
This report contains Public Security information  
Everyone can see this security related information.

Other bug subscribers

Remote bug watches

Bug watches keep track of this bug in other bug trackers.