Mahara 1.5.8

Milestone information

Project:
Mahara
Series:
1.5
Version:
1.5.8
Released:
 
Registrant:
Melissa Draper
Release registered:
Active:
No. Drivers cannot target bugs and blueprints to this milestone.  

Download RDF metadata

Activities

Assigned to you:
No blueprints or bugs assigned to you.
Assignees:
2 Aaron Wells, 1 Melissa Draper, 1 Ruslan Kabalin, 1 Son Nguyen
Blueprints:
No blueprints are targeted to this milestone.
Bugs:
6 Fix Released

Download files for this release

File Description Downloads

Release notes 

Mahara 1.5.8 Release Notes

This is a stable release of Mahara 1.5. Stable releases are fit for
general use. If you find a bug, please report it to the tracker:

https://bugs.launchpad.net/mahara/+filebug

This release includes an upgrade path from 1.0. If you wish to
upgrade, we encourage you to make a copy of your website and test the
upgrade on it first, to minimise the effect of any potential
unforeseen problems.

Changes from 1.5.7:

* flowplayer: Updating flowplayer with custom build to disallow absolute URLs in config parameters
* internalmedia/lib.php: Changing flowplayer invocation to only use relative URLs
* Remove 'safe' function from template to prevent xss (Bug #1091764)
* Additional processing fixes for rss to avoid fatal errors (Bug #1081431)
* Fix double encoding of & in 'url' for a pagination (Bug #1090203)
* Fix pagination double encoding (bug #1089282)
* Remove useragent from sso session check (Bug #1082416)

Changelog 

View the full changelog

flowplayer: Updating flowplayer with custom build to disallow absolute URLs in config parameters
internalmedia/lib.php: Changing flowplayer invocation to only use relative URLs
Remove 'safe' function from template to prevent xss (Bug #1091764)
Additional processing fixes for rss to avoid fatal errors (Bug #1081431)
Fix double encoding of & in 'url' for a pagination (Bug #1090203)
Fix pagination double encoding (bug #1089282)
Remove useragent from sso session check (Bug #1082416)

0 blueprints and 6 bugs targeted

Bug report Importance Assignee Status
1103748 #1103748 included flowplayer 3.2.7 is vulnerable 2 Critical Aaron Wells  10 Fix Released
1081431 #1081431 rss fails to update feeds 3 High Melissa Draper  10 Fix Released
1089282 #1089282 Pagination links are broken due to encoding of encoded ampersands 3 High Ruslan Kabalin  10 Fix Released
1090203 #1090203 Double encoding of & in 'url' for pagination causes pagination links to be broken 3 High Son Nguyen  10 Fix Released
1091764 #1091764 Cross site Scripting(XSS) Vulnerability in Mahara 1.6 3 High Aaron Wells  10 Fix Released
1082416 #1082416 XMLRPC with Firefox 17.0 not possible 1 Undecided   10 Fix Released
This milestone contains Public information
Everyone can see this information.