diff -Nru ubiquity-slideshow-ubuntu-58.1/debian/changelog ubiquity-slideshow-ubuntu-58.2/debian/changelog --- ubiquity-slideshow-ubuntu-58.1/debian/changelog 2012-08-15 16:37:48.000000000 +0000 +++ ubiquity-slideshow-ubuntu-58.2/debian/changelog 2012-08-15 19:52:51.000000000 +0000 @@ -1,3 +1,11 @@ +ubiquity-slideshow-ubuntu (58.2) precise-security; urgency=low + + * Previous fix still allows for https MITM by not checking the SSL + certificate. So turn off twitter completely for now. (LP: #991982) + CVE-2012-0956 + + -- Stéphane Graber Wed, 15 Aug 2012 15:50:32 -0400 + ubiquity-slideshow-ubuntu (58.1) precise-security; urgency=low [ Dylan McCall ] diff -Nru ubiquity-slideshow-ubuntu-58.1/slideshows/oem-config-ubuntu/slides/link/twitter.js ubiquity-slideshow-ubuntu-58.2/slideshows/oem-config-ubuntu/slides/link/twitter.js --- ubiquity-slideshow-ubuntu-58.1/slideshows/oem-config-ubuntu/slides/link/twitter.js 2012-08-15 16:37:48.000000000 +0000 +++ ubiquity-slideshow-ubuntu-58.2/slideshows/oem-config-ubuntu/slides/link/twitter.js 2012-08-15 19:52:51.000000000 +0000 @@ -330,6 +330,9 @@ doTwitter = false; } +// Turn off Twitter for security reason +doTwitter = false; + Signals.watch('slideshow-loaded', function() { if (doTwitter) { $('.twitter-stream').each(function(index, streamContainer) { diff -Nru ubiquity-slideshow-ubuntu-58.1/slideshows/ubuntu/slides/link/twitter.js ubiquity-slideshow-ubuntu-58.2/slideshows/ubuntu/slides/link/twitter.js --- ubiquity-slideshow-ubuntu-58.1/slideshows/ubuntu/slides/link/twitter.js 2012-08-15 16:37:48.000000000 +0000 +++ ubiquity-slideshow-ubuntu-58.2/slideshows/ubuntu/slides/link/twitter.js 2012-08-15 19:52:51.000000000 +0000 @@ -330,6 +330,9 @@ doTwitter = false; } +// Turn off Twitter for security reason +doTwitter = false; + Signals.watch('slideshow-loaded', function() { if (doTwitter) { $('.twitter-stream').each(function(index, streamContainer) {