drupal6: please allow transition to lenny
Hi releasers,
I would like to ask for allowance of drupal6_6.6-2 in lenny. This
release acknowledges NMU from Patrick and fixes a couple of bugs that
affect druapl6 when installed alongside drupal5 and with postgres
backend.
This is the relevant changelog entry:
drupal6 (6.6-2) unstable; urgency=high
* debian/patches/12_SA-2008-073
- Moved NMU changes to dpatch file
* debian/control
- Added dependency on ${misc:Depends} to make lintian happy
* debian/drupal6.{postinst,postrm}
- Changed apache configuration link name to drupal6.conf, to avoid
collision with drupal5 (Closes: #509769, #505146)
- Set default Postgres encoding to UTF8 (Closes: #508506)
* debian/README.Debian
- Fixed link to installation script (Closes: 507914)
-- Luigi Gangitano <luigi@debian.org> Thu, 08 Jan 2009 20:49:51 +0100
drupal6 (6.6-1.1) unstable; urgency=high
* Non-maintainer upload.
* Urgency high because this fixes a security issue
* Include upstream patch for SA-2008-073, to fix a security issue:
The update system is vulnerable to Cross site request forgeries.
Malicious
users may cause the superuser (user 1) to execute old updates
that may
damage the database.
(Ref: SA-2008-073) (Closes: #508473)
-- Patrick Schoenfeld <schoenfeld@debian.org> Fri, 12 Dec 2008
09:30:28 +0100
Thanks,
L
--
Luigi Gangitano -- <luigi@debian.org> -- <gangitano@lugroma3.org>
GPG: 1024D/924C0C26: 12F8 9C03 89D3 DB4A 9972 C24A F19B A618 924C 0C26
Reply to: