Mahara 1.0.14

Milestone information

Fran├žois Marier
Release registered:
No. Drivers cannot target bugs and blueprints to this milestone.  

Download RDF metadata


Assigned to you:
No blueprints or bugs assigned to you.
2 Evan Goldenberg
No blueprints are targeted to this milestone.
2 Fix Released

Download files for this release

After you've downloaded a file, you can verify its authenticity using its MD5 sum or signature. (How do I verify a download?)

File Description Downloads
download icon (md5, sig) release tarball 20
last downloaded 62 weeks ago
download icon mahara-1.0.14.tar.bz2 (md5, sig) release tarball 11
last downloaded 62 weeks ago
download icon mahara-1.0.14.tar.gz (md5, sig) release tarball 16
last downloaded 62 weeks ago
Total downloads: 47

Release notes 

Mahara 1.0.14 Release Notes

This is a stable release of Mahara 1.0. Stable releases are fit for
general use. If you find a bug, please report it to the tracker:

This release includes an upgrade path from 1.0. If you wish to
upgrade, we encourage you to make a copy of your website and test the
upgrade on it first, to minimise the effect of any potential
unforeseen problems.

Changes from 1.0.13:

 * Security fixes to bundled copy of smarty (CVE-2008-4810, CVE-2008-4811 and CVE-2009-1669)
 * Fix for SQL injection in MNET usernames (CVE-2010-0400)


View the full changelog

security fix: patch two smarty vulnerabilities (bug #491129)
Security fix: use a placeholder to escape username

0 blueprints and 2 bugs targeted

Bug report Importance Assignee Status
534172 #534172 get_new_username() does not escape string used in SQL call 2 Critical Evan Goldenberg  10 Fix Released
491129 #491129 Smarty version in Mahara 1.0 and 1.1 has security vulnerabilities 1 Undecided Evan Goldenberg  10 Fix Released
This milestone contains Public information
Everyone can see this information.