Link [ pkgsrc | NetBSD | pkgsrc git mirror | PR fulltext-search | netbsd commit viewer ]


   
        usage: [branch:branch] [user:user] [path[@revision]] keyword [... [-excludekeyword [...]]] (e.g. branch:MAIN pkgtools/pkg)




switch to index mode

recent branches: MAIN (2m)  pkgsrc-2024Q1 (9d)  pkgsrc-2023Q4 (56d)  pkgsrc-2023Q2 (88d)  pkgsrc-2023Q3 (167d) 

2024-05-26 15:48:11 UTC Now

2012-06-01 12:12:26 UTC pkgsrc-2012Q1 commitmail json YAML

Pullup ticket #3814 - requested by obache
www/moodle:: security update

Revisions pulled up:
- www/moodle/Makefile                                          1.11
- www/moodle/PLIST                                              1.9
- www/moodle/distinfo                                          1.9

---
  Module Name: pkgsrc
  Committed By: obache
  Date: Thu May 31 12:12:54 UTC 2012

  Modified Files:
  pkgsrc/www/moodle: Makefile PLIST distinfo

  Log Message:
  Update moodle to 2.1.6, include some security fixes.
  Based on maintainer update request by PR 46498.

  Upstream changes:

  Highlights

  * MDL-32431 Calendar events can be backed-up and restored
  * MDL-29262 Moodle 2 backup_controllers table is no longer needlessly massive

  Functional changes

  * MDL-27862 Ability to unset a theme
  * MDL-31835 Recent conversations link added when viewing a message
  * MDL-27427 Option added to delete external blog entries

  Security issues

  * MSA-12-0024 Hidden information access issue
  * MSA-12-0025 Personal communication access issue
  * MSA-12-0026 Quiz capability issue
  * MSA-12-0027 Question bank capability issues
  * MSA-12-0028 Insecure authentication issue
  * MSA-12-0029 Information editing access issue
  * MSA-12-0030 Capability manipulation issue
  * MSA-12-0031 Cross-site scripting vulnerability in Wiki
  * MSA-12-0032 Cross-site scripting vulnerability in Web services
  * MSA-12-0035 Cross-site scripting vulnerability in "download all"
  * MSA-12-0036 Cross-site scripting vulnerability in category identifier
  * MSA-12-0037 Write access issue in Database activity module
  * MSA-12-0038 Calendar event write permission issue

  Fixes and improvements

  * MDL-32061 Backup fixed when there is a lesson with attempts in the course
  * MDL-31008 CSS fixed to display dimmed objects
  * MDL-30867 Lesson essay question formatting fixed
  * MDL-31528 Breadcrumbs appearing consistently when editing is off
  * MDL-31631 Caching fixed so deleted activities do not remain listed
  * MDL-26674 Wiki Module activity logs activity fully
  * MDL-31510 Students in groups see only assignments in the Gradebook according to their group allocation
  * MDL-32141 Custom TinyMCE additions now work in Firefox 11

(tron)