<?xml version="1.0"?>
<rss xmlns:dc="http://purl.org/dc/elements/1.1/" version="2.0">
  <channel>
    <title>Transition Technology: Ticket Query</title>
    <link>http://localhost:8080/trac/query?status=closed&amp;component=Mediawiki&amp;milestone=Maintenance&amp;group=resolution&amp;desc=1&amp;order=id</link>
    <description>Support and issues tracking for the Transition Network Web Project.</description>
    <language>en-US</language>
    <image>
      <title>Transition Technology</title>
      <url>/trac/chrome/site/TransitionNetwork-Logo-Web-Small.jpg</url>
      <link>http://localhost:8080/trac/query?status=closed&amp;component=Mediawiki&amp;milestone=Maintenance&amp;group=resolution&amp;desc=1&amp;order=id</link>
    </image>
    <generator>Trac 0.12.5</generator>
    <item>
        <link>http://localhost:8080/trac/ticket/841</link>
        <guid isPermaLink="false">http://localhost:8080/trac/ticket/841</guid>
        <title>#841: Mediawiki 1.23.9</title>
        <pubDate>Wed, 01 Apr 2015 20:26:50 GMT</pubDate>
        
        <dc:creator>chris</dc:creator>

        <description>&lt;p&gt;
Email on &lt;a class="ext-link" href="https://lists.wikimedia.org/pipermail/mediawiki-announce/2015-March/000175.html"&gt;&lt;span class="icon"&gt;​&lt;/span&gt;the announcements list&lt;/a&gt;:
&lt;/p&gt;
&lt;blockquote class="citation"&gt;
&lt;p&gt;
I would like to announce the release of &lt;a class="wiki" href="http://localhost:8080/trac/wiki/MediaWiki"&gt;MediaWiki&lt;/a&gt; 1.24.2, 1.23.9 and 1.19.24. These releases fix 10 security issues, in addition to other bug fixes. Download links are given at the end of this email.
&lt;/p&gt;
&lt;h2 id="Securityfixes"&gt;Security fixes&lt;/h2&gt;
&lt;ul&gt;&lt;li&gt;iSEC Partners discovered a way to circumvent the SVG MIME blacklist for embedded resources (iSEC-WMF1214-11). This allowed an attacker to embed JavaScript in the SVG. The issue was additionally identified by Mario Heiderich / Cure53. MIME types are now whitelisted.  &lt;a class="ext-link" href="https://phabricator.wikimedia.org/T85850"&gt;&lt;span class="icon"&gt;​&lt;/span&gt;https://phabricator.wikimedia.org/T85850&lt;/a&gt;
&lt;/li&gt;&lt;li&gt;&lt;a class="wiki" href="http://localhost:8080/trac/wiki/MediaWiki"&gt;MediaWiki&lt;/a&gt; user Bawolff pointed out that the SVG filter to prevent injecting JavaScript using animate elements was incorrect.  &lt;a class="ext-link" href="https://phabricator.wikimedia.org/T86711"&gt;&lt;span class="icon"&gt;​&lt;/span&gt;https://phabricator.wikimedia.org/T86711&lt;/a&gt;
&lt;/li&gt;&lt;li&gt;&lt;a class="wiki" href="http://localhost:8080/trac/wiki/MediaWiki"&gt;MediaWiki&lt;/a&gt; user Bawolff reported a stored XSS vulnerability due to the way attributes were expanded in &lt;a class="wiki" href="http://localhost:8080/trac/wiki/MediaWiki"&gt;MediaWiki&lt;/a&gt;'s Html class, in combination with LanguageConverter substitutions.  &lt;a class="ext-link" href="https://phabricator.wikimedia.org/T73394"&gt;&lt;span class="icon"&gt;​&lt;/span&gt;https://phabricator.wikimedia.org/T73394&lt;/a&gt;
&lt;/li&gt;&lt;li&gt;Internal review discovered that &lt;a class="wiki" href="http://localhost:8080/trac/wiki/MediaWiki"&gt;MediaWiki&lt;/a&gt;'s SVG filtering could be bypassed with entity encoding under the Zend interpreter. This could be used to inject JavaScript. This issue was also discovered by Mario Gomes from Beyond Security.  &lt;a class="ext-link" href="https://phabricator.wikimedia.org/T88310"&gt;&lt;span class="icon"&gt;​&lt;/span&gt;https://phabricator.wikimedia.org/T88310&lt;/a&gt;
&lt;/li&gt;&lt;li&gt;iSEC Partners discovered a XSS vulnerability in the way api errors were reflected when running under HHVM versions before 3.6.1 (iSEC-WMF1214-8).  &lt;a class="wiki" href="http://localhost:8080/trac/wiki/MediaWiki"&gt;MediaWiki&lt;/a&gt; now detects and mitigates this issue on older versions of HHVM.  &lt;a class="ext-link" href="https://phabricator.wikimedia.org/T85851"&gt;&lt;span class="icon"&gt;​&lt;/span&gt;https://phabricator.wikimedia.org/T85851&lt;/a&gt;
&lt;/li&gt;&lt;li&gt;Internal review and iSEC Partners discovered (iSEC-WMF1214-1) that &lt;a class="wiki" href="http://localhost:8080/trac/wiki/MediaWiki"&gt;MediaWiki&lt;/a&gt; versions using PBKDF2 for password hashing (the default since 1.24) are vulnerable to DoS attacks using extremely long passwords.  &lt;a class="ext-link" href="https://phabricator.wikimedia.org/T64685"&gt;&lt;span class="icon"&gt;​&lt;/span&gt;https://phabricator.wikimedia.org/T64685&lt;/a&gt;
&lt;/li&gt;&lt;li&gt;iSEC Partners discovered that &lt;a class="wiki" href="http://localhost:8080/trac/wiki/MediaWiki"&gt;MediaWiki&lt;/a&gt;'s SVG and XMP parsing, running under HHVM, was susceptible to "Billion Laughs" DoS attacks (iSEC-WMF1214-13).  &lt;a class="ext-link" href="https://phabricator.wikimedia.org/T85848"&gt;&lt;span class="icon"&gt;​&lt;/span&gt;https://phabricator.wikimedia.org/T85848&lt;/a&gt;
&lt;/li&gt;&lt;li&gt;Internal review found that &lt;a class="wiki" href="http://localhost:8080/trac/wiki/MediaWiki"&gt;MediaWiki&lt;/a&gt; is vulnerable to "Quadratic Blowup" DoS attacks, under both HHVM and Zend PHP.  &lt;a class="ext-link" href="https://phabricator.wikimedia.org/T71210"&gt;&lt;span class="icon"&gt;​&lt;/span&gt;https://phabricator.wikimedia.org/T71210&lt;/a&gt;
&lt;/li&gt;&lt;li&gt;iSEC Partners discovered a way to bypass the style filtering for SVG files (iSEC-WMF1214-3). This could violate the anonymity of users viewing the SVG.  &lt;a class="ext-link" href="https://phabricator.wikimedia.org/T85349"&gt;&lt;span class="icon"&gt;​&lt;/span&gt;https://phabricator.wikimedia.org/T85349&lt;/a&gt;
&lt;/li&gt;&lt;li&gt;iSEC Partners reported that the &lt;a class="wiki" href="http://localhost:8080/trac/wiki/MediaWiki"&gt;MediaWiki&lt;/a&gt; feature allowing a user to preview another user's custom JavaScript could be abused for privilege escalation (iSEC-WMF1214-10). This feature has been removed.  &lt;a class="ext-link" href="https://phabricator.wikimedia.org/T85855"&gt;&lt;span class="icon"&gt;​&lt;/span&gt;https://phabricator.wikimedia.org/T85855&lt;/a&gt;
&lt;/li&gt;&lt;/ul&gt;&lt;p&gt;
Additionally, the following extensions have been updated to fix security issues:
&lt;/p&gt;
&lt;ul&gt;&lt;li&gt;Extension:Scribunto - &lt;a class="wiki" href="http://localhost:8080/trac/wiki/MediaWiki"&gt;MediaWiki&lt;/a&gt; user Jackmcbarn discovered that function names were not sanitized in Lua error backtraces, which could lead to XSS.  &lt;a class="ext-link" href="https://phabricator.wikimedia.org/T85113"&gt;&lt;span class="icon"&gt;​&lt;/span&gt;https://phabricator.wikimedia.org/T85113&lt;/a&gt;
&lt;/li&gt;&lt;li&gt;Extension:!CheckUser - iSEC Partners discovered that the CheckUser extension did not prevent CSRF attacks on the form allowing checkusers to look up sensitive information about other users (iSEC-WMF1214-6). Since the use of CheckUser is logged, the CSRF could be abused to defame a trusted user or flood the logs with noise.  &lt;a class="ext-link" href="https://phabricator.wikimedia.org/T85858"&gt;&lt;span class="icon"&gt;​&lt;/span&gt;https://phabricator.wikimedia.org/T85858&lt;/a&gt;
&lt;/li&gt;&lt;/ul&gt;&lt;h2 id="Bugfixes"&gt;Bug fixes&lt;/h2&gt;
&lt;h3 id="a1.24"&gt;1.24&lt;/h3&gt;
&lt;ul&gt;&lt;li&gt;Fix case of SpecialAllPages/SpecialAllMessages in SpecialPageFactory to fix loading these special pages when $wgAutoloadAttemptLowercase is false.
&lt;/li&gt;&lt;li&gt;(bug T76254) Fix deleting of pages with PostgreSQL. Requires a schema change and running update.php to fix.
&lt;/li&gt;&lt;/ul&gt;&lt;h3 id="a1.231.24"&gt;1.23 &amp;amp; 1.24&lt;/h3&gt;
&lt;ul&gt;&lt;li&gt;(bug T70087) Fix Special:ActiveUsers page for installations using PostgreSQL.
&lt;/li&gt;&lt;/ul&gt;&lt;hr /&gt;
&lt;p&gt;
Full release notes:
&lt;/p&gt;
&lt;ul&gt;&lt;li&gt;&lt;a class="ext-link" href="https://www.mediawiki.org/wiki/Release_notes/1.24"&gt;&lt;span class="icon"&gt;​&lt;/span&gt;https://www.mediawiki.org/wiki/Release_notes/1.24&lt;/a&gt;
&lt;/li&gt;&lt;li&gt;&lt;a class="ext-link" href="https://www.mediawiki.org/wiki/Release_notes/1.23"&gt;&lt;span class="icon"&gt;​&lt;/span&gt;https://www.mediawiki.org/wiki/Release_notes/1.23&lt;/a&gt;
&lt;/li&gt;&lt;li&gt;&lt;a class="ext-link" href="https://www.mediawiki.org/wiki/Release_notes/1.19"&gt;&lt;span class="icon"&gt;​&lt;/span&gt;https://www.mediawiki.org/wiki/Release_notes/1.19&lt;/a&gt;
&lt;/li&gt;&lt;/ul&gt;&lt;p&gt;
Download:
&lt;/p&gt;
&lt;ul&gt;&lt;li&gt;&lt;a class="ext-link" href="http://download.wikimedia.org/mediawiki/1.24/mediawiki-1.24.2.tar.gz"&gt;&lt;span class="icon"&gt;​&lt;/span&gt;http://download.wikimedia.org/mediawiki/1.24/mediawiki-1.24.2.tar.gz&lt;/a&gt;
&lt;/li&gt;&lt;li&gt;&lt;a class="ext-link" href="http://download.wikimedia.org/mediawiki/1.23/mediawiki-1.23.9.tar.gz"&gt;&lt;span class="icon"&gt;​&lt;/span&gt;http://download.wikimedia.org/mediawiki/1.23/mediawiki-1.23.9.tar.gz&lt;/a&gt;
&lt;/li&gt;&lt;li&gt;&lt;a class="ext-link" href="http://download.wikimedia.org/mediawiki/1.19/mediawiki-1.19.24.tar.gz"&gt;&lt;span class="icon"&gt;​&lt;/span&gt;http://download.wikimedia.org/mediawiki/1.19/mediawiki-1.19.24.tar.gz&lt;/a&gt;
&lt;/li&gt;&lt;/ul&gt;&lt;p&gt;
Patch to previous version:
&lt;/p&gt;
&lt;ul&gt;&lt;li&gt;&lt;a class="ext-link" href="http://download.wikimedia.org/mediawiki/1.24/mediawiki-1.24.2.patch.gz"&gt;&lt;span class="icon"&gt;​&lt;/span&gt;http://download.wikimedia.org/mediawiki/1.24/mediawiki-1.24.2.patch.gz&lt;/a&gt;
&lt;/li&gt;&lt;li&gt;&lt;a class="ext-link" href="http://download.wikimedia.org/mediawiki/1.23/mediawiki-1.23.9.patch.gz"&gt;&lt;span class="icon"&gt;​&lt;/span&gt;http://download.wikimedia.org/mediawiki/1.23/mediawiki-1.23.9.patch.gz&lt;/a&gt;
&lt;/li&gt;&lt;li&gt;&lt;a class="ext-link" href="http://download.wikimedia.org/mediawiki/1.19/mediawiki-1.19.24.patch.gz"&gt;&lt;span class="icon"&gt;​&lt;/span&gt;http://download.wikimedia.org/mediawiki/1.19/mediawiki-1.19.24.patch.gz&lt;/a&gt;
&lt;/li&gt;&lt;/ul&gt;&lt;p&gt;
GPG signatures:
&lt;/p&gt;
&lt;ul&gt;&lt;li&gt;&lt;a class="ext-link" href="http://download.wikimedia.org/mediawiki/1.24/mediawiki-1.24.2.tar.gz.sig"&gt;&lt;span class="icon"&gt;​&lt;/span&gt;http://download.wikimedia.org/mediawiki/1.24/mediawiki-1.24.2.tar.gz.sig&lt;/a&gt;
&lt;/li&gt;&lt;li&gt;&lt;a class="ext-link" href="http://download.wikimedia.org/mediawiki/1.24/mediawiki-1.24.2.patch.gz.sig"&gt;&lt;span class="icon"&gt;​&lt;/span&gt;http://download.wikimedia.org/mediawiki/1.24/mediawiki-1.24.2.patch.gz.sig&lt;/a&gt;
&lt;/li&gt;&lt;li&gt;&lt;a class="ext-link" href="http://download.wikimedia.org/mediawiki/1.23/mediawiki-1.23.9.tar.gz.sig"&gt;&lt;span class="icon"&gt;​&lt;/span&gt;http://download.wikimedia.org/mediawiki/1.23/mediawiki-1.23.9.tar.gz.sig&lt;/a&gt;
&lt;/li&gt;&lt;li&gt;&lt;a class="ext-link" href="http://download.wikimedia.org/mediawiki/1.23/mediawiki-1.23.9.patch.gz.sig"&gt;&lt;span class="icon"&gt;​&lt;/span&gt;http://download.wikimedia.org/mediawiki/1.23/mediawiki-1.23.9.patch.gz.sig&lt;/a&gt;
&lt;/li&gt;&lt;li&gt;&lt;a class="ext-link" href="http://download.wikimedia.org/mediawiki/1.19/mediawiki-1.19.24.tar.gz.sig"&gt;&lt;span class="icon"&gt;​&lt;/span&gt;http://download.wikimedia.org/mediawiki/1.19/mediawiki-1.19.24.tar.gz.sig&lt;/a&gt;
&lt;/li&gt;&lt;li&gt;&lt;a class="ext-link" href="http://download.wikimedia.org/mediawiki/1.19/mediawiki-1.19.24.patch.gz.sig"&gt;&lt;span class="icon"&gt;​&lt;/span&gt;http://download.wikimedia.org/mediawiki/1.19/mediawiki-1.19.24.patch.gz.sig&lt;/a&gt;
&lt;/li&gt;&lt;/ul&gt;&lt;p&gt;
Extensions:
&lt;/p&gt;
&lt;ul&gt;&lt;li&gt;&lt;a class="ext-link" href="http://www.mediawiki.org/wiki/Extension:Scribunto"&gt;&lt;span class="icon"&gt;​&lt;/span&gt;http://www.mediawiki.org/wiki/Extension:Scribunto&lt;/a&gt;
&lt;/li&gt;&lt;li&gt;&lt;a class="ext-link" href="http://www.mediawiki.org/wiki/Extension:CheckUser"&gt;&lt;span class="icon"&gt;​&lt;/span&gt;http://www.mediawiki.org/wiki/Extension:CheckUser&lt;/a&gt;
&lt;/li&gt;&lt;/ul&gt;&lt;p&gt;
Public keys:
&lt;/p&gt;
&lt;ul&gt;&lt;li&gt;&lt;a class="ext-link" href="https://www.mediawiki.org/keys/keys.html"&gt;&lt;span class="icon"&gt;​&lt;/span&gt;https://www.mediawiki.org/keys/keys.html&lt;/a&gt;
&lt;/li&gt;&lt;/ul&gt;&lt;/blockquote&gt;
</description>
        <category>Results</category>
        <comments>http://localhost:8080/trac/ticket/841#changelog</comments>
    </item><item>
        <link>http://localhost:8080/trac/ticket/816</link>
        <guid isPermaLink="false">http://localhost:8080/trac/ticket/816</guid>
        <title>#816: MediaWiki 1.23.8</title>
        <pubDate>Thu, 18 Dec 2014 11:20:43 GMT</pubDate>
        
        <dc:creator>chris</dc:creator>

        <description>&lt;p&gt;
The &lt;a class="ext-link" href="https://lists.wikimedia.org/pipermail/mediawiki-announce/2014-December/000173.html"&gt;&lt;span class="icon"&gt;​&lt;/span&gt;announcement email&lt;/a&gt;:
&lt;/p&gt;
&lt;blockquote class="citation"&gt;
&lt;p&gt;
I would like to announce the release of &lt;a class="wiki" href="http://localhost:8080/trac/wiki/MediaWiki"&gt;MediaWiki&lt;/a&gt; 1.24.1, 1.23.8, 1.22.15 and 1.19.23. This is a regular security and maintenance release. Download links are given at the end of this email. Please note this release marks the end of lifetime for &lt;a class="wiki" href="http://localhost:8080/trac/wiki/MediaWiki"&gt;MediaWiki&lt;/a&gt; 1.22 branch.
&lt;/p&gt;
&lt;h2 id="Securityfixesin1.24.11.23.81.22.15and1.19.23"&gt;Security fixes in 1.24.1, 1.23.8, 1.22.15 and 1.19.23&lt;/h2&gt;
&lt;ul&gt;&lt;li&gt;(bug T76686) [SECURITY] thumb.php outputs wikitext message as raw HTML,
which could lead to xss. Permission to edit &lt;a class="wiki" href="http://localhost:8080/trac/wiki/MediaWiki"&gt;MediaWiki&lt;/a&gt; namespace is required
to exploit this.
&lt;/li&gt;&lt;li&gt;(bug T77028) [SECURITY] Malicious site can bypass CORS restrictions in
$wgCrossSiteAJAXdomains in API calls if it only included an allowed domain as
part of its name.
&lt;/li&gt;&lt;/ul&gt;&lt;h2 id="Bugfixes"&gt;Bugfixes&lt;/h2&gt;
&lt;ul&gt;&lt;li&gt;(bug T74222) The original patch for T74222 was reverted as unnecessary.
&lt;/li&gt;&lt;li&gt;Fixed a couple of entries in RELEASE-NOTES-1.24.
&lt;/li&gt;&lt;li&gt;(bug T76168) OutputPage: Add accessors for some protected properties.
&lt;/li&gt;&lt;li&gt;(bug T74834) Make 1.24 branch directly installable under PostgreSQL.
&lt;/li&gt;&lt;li&gt;Add missing $ in front of variable in OutputPage.php
&lt;/li&gt;&lt;/ul&gt;&lt;h2 id="Securityfixesinextensions"&gt;Security fixes in extensions&lt;/h2&gt;
&lt;ul&gt;&lt;li&gt;(bug T77624) [SECURITY] Extension:Listings: missing validation in the
'name' and 'url' parameters.
&lt;/li&gt;&lt;li&gt;(bug T73111) [SECURITY] Extension:ExpandTemplates: parses user input
as wikitext and shows a preview, yet it fails to add an edit token to
the form and check it. This can be exploited as an XSS when
$wgRawHtml = true. Note this only affects the 1.19/1.22 branches.
&lt;/li&gt;&lt;li&gt;(bug T76195) [SECURITY] Extension:TemplateSandbox:
Special:TemplateSandbox needs edit token when raw HTML is allowed
&lt;/li&gt;&lt;li&gt;(bug T69180) [SECURITY] Extension:Hovercards: XSS in text extracts.
&lt;/li&gt;&lt;li&gt;(bug T73167) [SECURITY] Extension:Scribunto allows cross-origin
leakage of data from a wiki through timing
&lt;/li&gt;&lt;li&gt;(bug T71209) [SECURITY] Extension:TimedMediaHandler: Patch getid3
library for CVE-2014-2053.
&lt;/li&gt;&lt;/ul&gt;&lt;p&gt;
Full release notes for 1.23.8:
&lt;a class="ext-link" href="https://www.mediawiki.org/wiki/Release_notes/1.23"&gt;&lt;span class="icon"&gt;​&lt;/span&gt;https://www.mediawiki.org/wiki/Release_notes/1.23&lt;/a&gt;
&lt;/p&gt;
&lt;/blockquote&gt;
</description>
        <category>Results</category>
        <comments>http://localhost:8080/trac/ticket/816#changelog</comments>
    </item><item>
        <link>http://localhost:8080/trac/ticket/813</link>
        <guid isPermaLink="false">http://localhost:8080/trac/ticket/813</guid>
        <title>#813: MediaWiki 1.23.7</title>
        <pubDate>Thu, 27 Nov 2014 14:38:47 GMT</pubDate>
        
        <dc:creator>chris</dc:creator>

        <description>&lt;p&gt;
The &lt;a class="ext-link" href="https://lists.wikimedia.org/pipermail/mediawiki-announce/2014-November/000170.html"&gt;&lt;span class="icon"&gt;​&lt;/span&gt;announcement email&lt;/a&gt;:
&lt;/p&gt;
&lt;p&gt;
I would like to announce the release of &lt;a class="wiki" href="http://localhost:8080/trac/wiki/MediaWiki"&gt;MediaWiki&lt;/a&gt; 1.23.7, 1.22.14 and 1.19.22. This is a regular security and maintenance release. Download links are given at the end of this email.
&lt;/p&gt;
&lt;blockquote class="citation"&gt;
&lt;h2 id="Securityfixes"&gt;Security fixes&lt;/h2&gt;
&lt;ul&gt;&lt;li&gt;(bugs 66776, 71478) SECURITY:  User PleaseStand reported a way to inject code into API clients that used format=php to process pages that underwent flash policy mangling. This was fixed along with improving how the mangling was done for format=json, and allowing sites to disable the mangling using $wgMangleFlashPolicy.  &lt;a class="ext-link" href="https://phabricator.wikimedia.org/T68776"&gt;&lt;span class="icon"&gt;​&lt;/span&gt;https://phabricator.wikimedia.org/T68776&lt;/a&gt; &lt;a class="ext-link" href="https://phabricator.wikimedia.org/T73478"&gt;&lt;span class="icon"&gt;​&lt;/span&gt;https://phabricator.wikimedia.org/T73478&lt;/a&gt;
&lt;/li&gt;&lt;/ul&gt;&lt;ul&gt;&lt;li&gt;(bug 70901) SECURITY: User Jackmcbarn reported that the ability to update the content model for a page could allow an unprivileged attacker to edit another user's common.js under certain circumstances. The user right "editcontentmodel" was added, and is needed to change a revision's content model.  &lt;a class="ext-link" href="https://phabricator.wikimedia.org/T72901"&gt;&lt;span class="icon"&gt;​&lt;/span&gt;https://phabricator.wikimedia.org/T72901&lt;/a&gt;
&lt;/li&gt;&lt;/ul&gt;&lt;ul&gt;&lt;li&gt;(bug 71111) SECURITY: User PleaseStand reported that on wikis that allow raw HTML, it is not safe to preview wikitext coming from an untrusted source such as a cross-site request. Thus add an edit token to the form, and when raw HTML is allowed, ensure the token is provided before showing the preview.  This check is not performed on wikis that both allow raw HTML and anonymous editing, since there are easier ways to exploit that scenario.  &lt;a class="ext-link" href="https://phabricator.wikimedia.org/T73111"&gt;&lt;span class="icon"&gt;​&lt;/span&gt;https://phabricator.wikimedia.org/T73111&lt;/a&gt;
&lt;/li&gt;&lt;/ul&gt;&lt;ul&gt;&lt;li&gt;(bug 72222) SECURITY: Do not show log action when the entry is revdeleted with DELETED_ACTION. NOTICE: this may be reverted in a future release pending a public RFC about the desired functionality. This issue was reported by user Bawolff.  &lt;a class="ext-link" href="https://phabricator.wikimedia.org/T74222"&gt;&lt;span class="icon"&gt;​&lt;/span&gt;https://phabricator.wikimedia.org/T74222&lt;/a&gt;
&lt;/li&gt;&lt;/ul&gt;&lt;h2 id="Bugfixes"&gt;Bugfixes&lt;/h2&gt;
&lt;ul&gt;&lt;li&gt;(bug 71621) Make allowing site-wide styles on restricted special pages a config option. &lt;a class="ext-link" href="https://phabricator.wikimedia.org/T73621"&gt;&lt;span class="icon"&gt;​&lt;/span&gt;https://phabricator.wikimedia.org/T73621&lt;/a&gt;
&lt;/li&gt;&lt;/ul&gt;&lt;ul&gt;&lt;li&gt;(bug 42723) Added updated version history from 1.19.2 to 1.22.13 &lt;a class="ext-link" href="https://phabricator.wikimedia.org/T44723"&gt;&lt;span class="icon"&gt;​&lt;/span&gt;https://phabricator.wikimedia.org/T44723&lt;/a&gt;
&lt;/li&gt;&lt;/ul&gt;&lt;ul&gt;&lt;li&gt;$wgMangleFlashPolicy was added to make &lt;a class="wiki" href="http://localhost:8080/trac/wiki/MediaWiki"&gt;MediaWiki&lt;/a&gt;'s mangling of anything that might be a flash policy directive configurable.
&lt;/li&gt;&lt;/ul&gt;&lt;p&gt;
Full release notes for 1.23.7:
&lt;a class="ext-link" href="https://www.mediawiki.org/wiki/Release_notes/1.23"&gt;&lt;span class="icon"&gt;​&lt;/span&gt;https://www.mediawiki.org/wiki/Release_notes/1.23&lt;/a&gt;
&lt;/p&gt;
&lt;/blockquote&gt;
</description>
        <category>Results</category>
        <comments>http://localhost:8080/trac/ticket/813#changelog</comments>
    </item><item>
        <link>http://localhost:8080/trac/ticket/799</link>
        <guid isPermaLink="false">http://localhost:8080/trac/ticket/799</guid>
        <title>#799: MediaWiki Visual Editor broken from Parsoid update</title>
        <pubDate>Tue, 21 Oct 2014 10:21:54 GMT</pubDate>
        
        <dc:creator>chris</dc:creator>

        <description>&lt;p&gt;
After updating Parasoid on &lt;a class="new ticket" href="http://localhost:8080/trac/ticket/692#comment:102" title="maintenance: Debian Updates (new)"&gt;ticket:692#comment:102&lt;/a&gt; the &lt;a class="wiki" href="http://localhost:8080/trac/wiki/MediaWiki"&gt;MediaWiki&lt;/a&gt; visual editor now generates this error:
&lt;/p&gt;
&lt;blockquote class="citation"&gt;
&lt;p&gt;
Error loading data from server: parsoidserver-http-bad-status: 500. Would you like to retry?
&lt;/p&gt;
&lt;/blockquote&gt;
</description>
        <category>Results</category>
        <comments>http://localhost:8080/trac/ticket/799#changelog</comments>
    </item><item>
        <link>http://localhost:8080/trac/ticket/793</link>
        <guid isPermaLink="false">http://localhost:8080/trac/ticket/793</guid>
        <title>#793: MediaWiki Security and Maintenance Release 1.23.5</title>
        <pubDate>Thu, 02 Oct 2014 08:57:49 GMT</pubDate>
        
        <dc:creator>chris</dc:creator>

        <description>&lt;p&gt;
Announcement &lt;a class="ext-link" href="https://lists.wikimedia.org/pipermail/mediawiki-announce/2014-October/000163.html"&gt;&lt;span class="icon"&gt;​&lt;/span&gt;email&lt;/a&gt;:
&lt;/p&gt;
&lt;blockquote class="citation"&gt;
&lt;p&gt;
I would like to announce the release of &lt;a class="wiki" href="http://localhost:8080/trac/wiki/MediaWiki"&gt;MediaWiki&lt;/a&gt; 1.19.20, 1.22.12 and 1.23.5. This is a security release. Download links are given at the end of this email.
&lt;/p&gt;
&lt;h2 id="Security"&gt;Security&lt;/h2&gt;
&lt;ul&gt;&lt;li&gt;(bug 70672) SECURITY: OutputPage: Remove separation of css and js module allowance.
&lt;/li&gt;&lt;/ul&gt;&lt;p&gt;
Full release notes for 1.23.5: &amp;lt;&lt;a class="ext-link" href="https://www.mediawiki.org/wiki/Release_notes/1.23"&gt;&lt;span class="icon"&gt;​&lt;/span&gt;https://www.mediawiki.org/wiki/Release_notes/1.23&lt;/a&gt;&amp;gt;
&lt;/p&gt;
&lt;/blockquote&gt;
</description>
        <category>Results</category>
        <comments>http://localhost:8080/trac/ticket/793#changelog</comments>
    </item><item>
        <link>http://localhost:8080/trac/ticket/781</link>
        <guid isPermaLink="false">http://localhost:8080/trac/ticket/781</guid>
        <title>#781: MediaWiki Security and Maintenance Releases: 1.22.10 and 1.23.3</title>
        <pubDate>Thu, 28 Aug 2014 06:42:16 GMT</pubDate>
        
        <dc:creator>chris</dc:creator>

        <description>&lt;p&gt;
Announcement email:
&lt;/p&gt;
&lt;ul&gt;&lt;li&gt;&lt;a class="ext-link" href="https://lists.wikimedia.org/pipermail/mediawiki-announce/2014-August/000159.html"&gt;&lt;span class="icon"&gt;​&lt;/span&gt;https://lists.wikimedia.org/pipermail/mediawiki-announce/2014-August/000159.html&lt;/a&gt;
&lt;/li&gt;&lt;/ul&gt;&lt;p&gt;
Bugfixes only, not a security update so no urgent update required.
&lt;/p&gt;
</description>
        <category>Results</category>
        <comments>http://localhost:8080/trac/ticket/781#changelog</comments>
    </item><item>
        <link>http://localhost:8080/trac/ticket/766</link>
        <guid isPermaLink="false">http://localhost:8080/trac/ticket/766</guid>
        <title>#766: MediaWiki Security and Maintenance Update 1.23.2</title>
        <pubDate>Wed, 30 Jul 2014 20:56:46 GMT</pubDate>
        
        <dc:creator>chris</dc:creator>

        <description>&lt;p&gt;
From the &lt;a class="ext-link" href="http://lists.wikimedia.org/pipermail/mediawiki-announce/2014-July/000157.html"&gt;&lt;span class="icon"&gt;​&lt;/span&gt;MediaWiki-announce&lt;/a&gt; list:
&lt;/p&gt;
&lt;blockquote class="citation"&gt;
&lt;p&gt;
I would like to announce the release of &lt;a class="wiki" href="http://localhost:8080/trac/wiki/MediaWiki"&gt;MediaWiki&lt;/a&gt; 1.23.2, 1.22.9 and 1.19.18. This is a regular security and maintenance release. Download links are given at the end of this email.
&lt;/p&gt;
&lt;h2 id="Security"&gt;Security&lt;/h2&gt;
&lt;ul&gt;&lt;li&gt;(bug 68187) SECURITY: Prepend jsonp callback with comment.
&lt;/li&gt;&lt;li&gt;(bug 66608) SECURITY: Fix for XSS issue in bug 66608: Generate the URL used for loading a new page in Javascript,instead of relying on the URL in the link that has been clicked.
&lt;/li&gt;&lt;li&gt;(bug 65778) SECURITY: Copy prevent-clickjacking between OutputPage and ParserOutput.
&lt;/li&gt;&lt;/ul&gt;&lt;h2 id="Bugfixesin1.23.2"&gt;Bugfixes in 1.23.2&lt;/h2&gt;
&lt;ul&gt;&lt;li&gt;(bug 68313) Preferences: Turn stubthreshold back into a combo box.
&lt;/li&gt;&lt;li&gt;(bug 65214) Fix initSiteStats.php maintenance script.
&lt;/li&gt;&lt;li&gt;(bug 67594) Special:ActiveUsers: Fix to work with PostgreSQL.
&lt;/li&gt;&lt;/ul&gt;&lt;p&gt;
Full release notes for 1.23.2:
&lt;a class="ext-link" href="https://www.mediawiki.org/wiki/Release_notes/1.23"&gt;&lt;span class="icon"&gt;​&lt;/span&gt;https://www.mediawiki.org/wiki/Release_notes/1.23&lt;/a&gt;
&lt;/p&gt;
&lt;p&gt;
Public keys:
&amp;lt;&lt;a class="ext-link" href="https://www.mediawiki.org/keys/keys.html"&gt;&lt;span class="icon"&gt;​&lt;/span&gt;https://www.mediawiki.org/keys/keys.html&lt;/a&gt;&amp;gt;
&lt;/p&gt;
&lt;h2 id="a1.23.2"&gt;1.23.2&lt;/h2&gt;
&lt;p&gt;
Download:
&lt;a class="ext-link" href="https://releases.wikimedia.org/mediawiki/1.23/mediawiki-1.23.2.tar.gz"&gt;&lt;span class="icon"&gt;​&lt;/span&gt;https://releases.wikimedia.org/mediawiki/1.23/mediawiki-1.23.2.tar.gz&lt;/a&gt;
&lt;/p&gt;
&lt;p&gt;
Patch to previous version (1.23.1):
&lt;a class="ext-link" href="https://releases.wikimedia.org/mediawiki/1.23/mediawiki-1.23.2.patch.gz"&gt;&lt;span class="icon"&gt;​&lt;/span&gt;https://releases.wikimedia.org/mediawiki/1.23/mediawiki-1.23.2.patch.gz&lt;/a&gt;
&lt;/p&gt;
&lt;p&gt;
GPG signatures:
&lt;a class="ext-link" href="https://releases.wikimedia.org/mediawiki/1.23/mediawiki-core-1.23.2.tar.gz.sig"&gt;&lt;span class="icon"&gt;​&lt;/span&gt;https://releases.wikimedia.org/mediawiki/1.23/mediawiki-core-1.23.2.tar.gz.sig&lt;/a&gt;
&lt;a class="ext-link" href="https://releases.wikimedia.org/mediawiki/1.23/mediawiki-1.23.2.tar.gz.sig"&gt;&lt;span class="icon"&gt;​&lt;/span&gt;https://releases.wikimedia.org/mediawiki/1.23/mediawiki-1.23.2.tar.gz.sig&lt;/a&gt;
&lt;a class="ext-link" href="https://releases.wikimedia.org/mediawiki/1.23/mediawiki-1.23.2.patch.gz.sig"&gt;&lt;span class="icon"&gt;​&lt;/span&gt;https://releases.wikimedia.org/mediawiki/1.23/mediawiki-1.23.2.patch.gz.sig&lt;/a&gt;
&lt;/p&gt;
&lt;p&gt;
Note:
There is no i18n patch as there are no changes in translation.
&lt;/p&gt;
&lt;/blockquote&gt;
</description>
        <category>Results</category>
        <comments>http://localhost:8080/trac/ticket/766#changelog</comments>
    </item><item>
        <link>http://localhost:8080/trac/ticket/753</link>
        <guid isPermaLink="false">http://localhost:8080/trac/ticket/753</guid>
        <title>#753: wiki.transitionnetwork.org displaying error</title>
        <pubDate>Fri, 04 Jul 2014 08:23:52 GMT</pubDate>
        
        <dc:creator>chris</dc:creator>

        <description>&lt;p&gt;
This is rather weird, the site was working yesterday, now at &lt;a class="ext-link" href="https://wiki.transitionnetwork.org/"&gt;&lt;span class="icon"&gt;​&lt;/span&gt;https://wiki.transitionnetwork.org/&lt;/a&gt; we have:
&lt;/p&gt;
&lt;pre class="wiki"&gt;bar(), etc etc) which throw parse errors in # PHP 4. Setup.php and ObjectCache.php have structures invalid in PHP 5.0 and # 5.1, respectively. if ( !function_exists( 'version_compare' ) || version_compare( phpversion(), '5.3.2' ) &amp;lt; 0 ) { // We need to use dirname( __FILE__ ) here cause __DIR__ is PHP5.3+ require dirname( __FILE__ ) . '/includes/PHPVersionError.php'; wfPHPVersionError( 'index.php' ); } require __DIR__ . '/includes/WebStart.php'; $mediaWiki = new MediaWiki(); $mediaWiki-&amp;gt;run();
&lt;/pre&gt;</description>
        <category>Results</category>
        <comments>http://localhost:8080/trac/ticket/753#changelog</comments>
    </item><item>
        <link>http://localhost:8080/trac/ticket/736</link>
        <guid isPermaLink="false">http://localhost:8080/trac/ticket/736</guid>
        <title>#736: Upgrade to MediaWiki 1.23.0</title>
        <pubDate>Thu, 05 Jun 2014 09:43:50 GMT</pubDate>
        
        <dc:creator>chris</dc:creator>

        <description>&lt;p&gt;
From &lt;a class="ext-link" href="http://lists.wikimedia.org/pipermail/mediawiki-announce/2014-June/000152.html"&gt;&lt;span class="icon"&gt;​&lt;/span&gt;the announcements list&lt;/a&gt;:
&lt;/p&gt;
&lt;blockquote class="citation"&gt;
&lt;p&gt;
I am happy to announce the availability of the first stable release of the new &lt;a class="wiki" href="http://localhost:8080/trac/wiki/MediaWiki"&gt;MediaWiki&lt;/a&gt; 1.23 release series.
&lt;/p&gt;
&lt;p&gt;
&lt;a class="wiki" href="http://localhost:8080/trac/wiki/MediaWiki"&gt;MediaWiki&lt;/a&gt; 1.23 is a large release that contains many new features and bug fixes. This is a summary of the major changes of interest to users. You can consult the RELEASE-NOTES-1.23 file for the full list of changes in this version.
&lt;/p&gt;
&lt;p&gt;
This is a Long Term Support release (LTS) and will be supported until May 2017.
&lt;/p&gt;
&lt;p&gt;
Our thanks to everyone who helped to improve &lt;a class="wiki" href="http://localhost:8080/trac/wiki/MediaWiki"&gt;MediaWiki&lt;/a&gt; by testing the release candidates and submitting bug reports.
&lt;/p&gt;
&lt;h2 id="Whatsnew"&gt;What's new?&lt;/h2&gt;
&lt;ul&gt;&lt;li&gt;&lt;a class="wiki" href="http://localhost:8080/trac/wiki/MediaWiki"&gt;MediaWiki&lt;/a&gt; 1.23 includes all changes released in the smaller 1.23wmfX software deployments to Wikimedia sites.
&lt;/li&gt;&lt;/ul&gt;&lt;h3 id="Skinautodiscoverydeprecated"&gt;Skin autodiscovery deprecated&lt;/h3&gt;
&lt;p&gt;
Skin autodiscovery, the legacy skin installation mechanism used by &lt;a class="wiki" href="http://localhost:8080/trac/wiki/MediaWiki"&gt;MediaWiki&lt;/a&gt; since very early versions (around 2004), has been officially deprecated and will be removed in &lt;a class="wiki" href="http://localhost:8080/trac/wiki/MediaWiki"&gt;MediaWiki&lt;/a&gt; 1.25.
&lt;/p&gt;
&lt;ul&gt;&lt;li&gt;&lt;a class="wiki" href="http://localhost:8080/trac/wiki/MediaWiki"&gt;MediaWiki&lt;/a&gt; 1.23 will emit warnings in production if a skin using the deprecated mechanism is found.
&lt;/li&gt;&lt;li&gt;See Manual:Skin autodiscovery for more information and a migration guide for site admins and skin developers.
&lt;/li&gt;&lt;/ul&gt;&lt;h3 id="Notifications"&gt;Notifications&lt;/h3&gt;
&lt;p&gt;
With 1.23, &lt;a class="wiki" href="http://localhost:8080/trac/wiki/MediaWiki"&gt;MediaWiki&lt;/a&gt; starts to behave more like a modern website as regards notifications, to keep the editors of your wiki engaged and always up to date about what interests them. This used to require several custom settings.
&lt;/p&gt;
&lt;ul&gt;&lt;li&gt;(bug 45020) Make preferences "Add pages I create and files I upload to my watchlist" and "pages and files I edit" true by default.
&lt;/li&gt;&lt;li&gt;(bug 45022) Make preference "Email me when a page or file on my watchlist is changed" true by default.
&lt;/li&gt;&lt;li&gt;(bug 49719) Watch user page and user talk page by default.
&lt;/li&gt;&lt;/ul&gt;&lt;p&gt;
This will allow your new users to immediately start benefiting from the watchlist and email notification features, without needing to first read all the docs to find out that they're as useful as they are.
&lt;/p&gt;
&lt;h3 id="Mergedextensions"&gt;Merged extensions&lt;/h3&gt;
&lt;p&gt;
Merged into 1.23:
&lt;/p&gt;
&lt;ul&gt;&lt;li&gt;ExpandTemplates (bug 28264).
&lt;/li&gt;&lt;li&gt;AssertEdit (bug 27841) - documented at API:Assert.
&lt;/li&gt;&lt;/ul&gt;&lt;h3 id="Interface"&gt;Interface&lt;/h3&gt;
&lt;ul&gt;&lt;li&gt;(bug 42026) Add option to only show page creations in Special:Contributions (and API).
&lt;/li&gt;&lt;li&gt;Add new special page to list duplicate files, Special:ListDuplicatedFiles.
&lt;/li&gt;&lt;li&gt;(bug 60333) Add new special page listing tracking categories (Special:TrackingCategories).
&lt;/li&gt;&lt;/ul&gt;&lt;h3 id="Editing"&gt;Editing&lt;/h3&gt;
&lt;ul&gt;&lt;li&gt;A new special page Special:Diff was added, allowing users to create internal links to revision comparison pages using syntax such as Special:Diff/12345, Special:Diff/12345/prev or Special:Diff/12345/98765.
&lt;/li&gt;&lt;/ul&gt;&lt;h3 id="Helppages"&gt;Help pages&lt;/h3&gt;
&lt;p&gt;
With 1.23, &lt;a class="wiki" href="http://localhost:8080/trac/wiki/MediaWiki"&gt;MediaWiki&lt;/a&gt; begins a process of consolidation of its help pages. Now, most are using the Translate extension and can be easily translated and updated in hundreds languages.
&lt;/p&gt;
&lt;p&gt;
In the coming months, we'll focus on making more of the central help pages translatable and on linking them from the relevant &lt;a class="wiki" href="http://localhost:8080/trac/wiki/MediaWiki"&gt;MediaWiki&lt;/a&gt; interfaces for better discoverability. Please help: add your own translations; update existing pages and cover missing &lt;a class="wiki" href="http://localhost:8080/trac/wiki/MediaWiki"&gt;MediaWiki&lt;/a&gt; topics.
&lt;/p&gt;
&lt;p&gt;
Traditionally, help pages have been scattered on countless wikis and poorly translated; most of those on mediawiki.org were migrated with the help of some Google Code-in students.
&lt;/p&gt;
&lt;h3 id="CSSrefreshforVector"&gt;CSS refresh for Vector&lt;/h3&gt;
&lt;ul&gt;&lt;li&gt;Various Vector CSS properties have been converted to LESS variables.
&lt;/li&gt;&lt;li&gt;The font size of &lt;tt&gt;#bodyContent&lt;/tt&gt;/&lt;tt&gt;.mw-body-content&lt;/tt&gt; has been increased to 0.875em.
&lt;/li&gt;&lt;li&gt;The line-height of &lt;tt&gt;#bodyContent&lt;/tt&gt;/&lt;tt&gt;.mw-body-content&lt;/tt&gt; has been increased to 1.6.
&lt;/li&gt;&lt;li&gt;The line-height of superscript (sup) and subscript (sub) are now set to 1.
&lt;/li&gt;&lt;li&gt;The default color for content text (but not the headers) is now #252525; (dark grey).
&lt;/li&gt;&lt;li&gt;All headers have updated sizes and margins.
&lt;/li&gt;&lt;li&gt;H1 and H2 headers now use a serif font.
&lt;/li&gt;&lt;li&gt;Body font is "sans-serif" as always.
&lt;/li&gt;&lt;/ul&gt;&lt;p&gt;
For more information see Typography refresh.
&lt;/p&gt;
&lt;h3 id="Configuration"&gt;Configuration&lt;/h3&gt;
&lt;p&gt;
Add Config and GlobalConfig classes:
&lt;/p&gt;
&lt;ul&gt;&lt;li&gt;Allows configuration options to be fetched from context.
&lt;/li&gt;&lt;li&gt;Only one implementation, GlobalConfig, is provided, which simply returns $GLOBALS[$name]. There can be more classes in the future, possibly a database-based one. For convinience the "wg" prefix is automatically added.
&lt;/li&gt;&lt;li&gt;This adds the $wgConfigClass global variable which is used to determine which implementation of Config to use by default.
&lt;/li&gt;&lt;li&gt;The ContextSource getConfig and setConfig methods were introduced.
&lt;/li&gt;&lt;/ul&gt;&lt;p&gt;
Full release notes:
&lt;a class="ext-link" href="https://git.wikimedia.org/blob/mediawiki%2Fcore.git/1.23.0/RELEASE-NOTES-1.23"&gt;&lt;span class="icon"&gt;​&lt;/span&gt;https://git.wikimedia.org/blob/mediawiki%2Fcore.git/1.23.0/RELEASE-NOTES-1.23&lt;/a&gt;
&lt;a class="ext-link" href="https://www.mediawiki.org/wiki/Release_notes/1.23"&gt;&lt;span class="icon"&gt;​&lt;/span&gt;https://www.mediawiki.org/wiki/Release_notes/1.23&lt;/a&gt;
&lt;/p&gt;
&lt;hr /&gt;
&lt;p&gt;
Download:
&lt;a class="ext-link" href="http://download.wikimedia.org/mediawiki/1.23/mediawiki-1.23.0.tar.gz"&gt;&lt;span class="icon"&gt;​&lt;/span&gt;http://download.wikimedia.org/mediawiki/1.23/mediawiki-1.23.0.tar.gz&lt;/a&gt;
&lt;/p&gt;
&lt;p&gt;
GPG signatures:
&lt;a class="ext-link" href="http://download.wikimedia.org/mediawiki/1.23/mediawiki-1.23.0.tar.gz.sig"&gt;&lt;span class="icon"&gt;​&lt;/span&gt;http://download.wikimedia.org/mediawiki/1.23/mediawiki-1.23.0.tar.gz.sig&lt;/a&gt;
&lt;/p&gt;
&lt;p&gt;
Public keys:
&lt;a class="ext-link" href="https://www.mediawiki.org/keys/keys.html"&gt;&lt;span class="icon"&gt;​&lt;/span&gt;https://www.mediawiki.org/keys/keys.html&lt;/a&gt;
&lt;/p&gt;
&lt;/blockquote&gt;
&lt;p&gt;
I'd suggest we upgrade to this version and then perhaps stick with it, only doing security updates, until we need to move to another version due to it no longer being supported or because we need some new functionality.
&lt;/p&gt;
</description>
        <category>Results</category>
        <comments>http://localhost:8080/trac/ticket/736#changelog</comments>
    </item><item>
        <link>http://localhost:8080/trac/ticket/733</link>
        <guid isPermaLink="false">http://localhost:8080/trac/ticket/733</guid>
        <title>#733: Mediawiki 1.22.7 security update</title>
        <pubDate>Sun, 01 Jun 2014 09:20:53 GMT</pubDate>
        
        <dc:creator>chris</dc:creator>

        <description>&lt;p&gt;
See &lt;a class="ext-link" href="https://www.mediawiki.org/wiki/Release_notes/1.22#MediaWiki_1.22.6"&gt;&lt;span class="icon"&gt;​&lt;/span&gt;https://www.mediawiki.org/wiki/Release_notes/1.22#MediaWiki_1.22.6&lt;/a&gt;
&lt;/p&gt;
</description>
        <category>Results</category>
        <comments>http://localhost:8080/trac/ticket/733#changelog</comments>
    </item><item>
        <link>http://localhost:8080/trac/ticket/723</link>
        <guid isPermaLink="false">http://localhost:8080/trac/ticket/723</guid>
        <title>#723: Mediawiki 1.22.6 Upgrade</title>
        <pubDate>Mon, 28 Apr 2014 10:10:48 GMT</pubDate>
        
        <dc:creator>chris</dc:creator>

        <description>&lt;p&gt;
Announced &lt;a class="ext-link" href="http://lists.wikimedia.org/pipermail/mediawiki-announce/2014-April/000149.html"&gt;&lt;span class="icon"&gt;​&lt;/span&gt;a few days ago&lt;/a&gt;:
&lt;/p&gt;
&lt;blockquote class="citation"&gt;
&lt;p&gt;
I would like to announce the release of &lt;a class="wiki" href="http://localhost:8080/trac/wiki/MediaWiki"&gt;MediaWiki&lt;/a&gt; 1.22.6 and 1.21.9. This is a regular security and maintenance release. Download links are given at the end of this email. Please note there is no new release of the 1.19 branch, as it is not affected by the security issue.
&lt;/p&gt;
&lt;h2 id="Security"&gt;Security&lt;/h2&gt;
&lt;ul&gt;&lt;li&gt;(bug 63251) SECURITY: escape sortKey in pageInfo.
&lt;/li&gt;&lt;/ul&gt;&lt;h2 id="Bugfixesin1.21.9"&gt;Bugfixes in 1.21.9&lt;/h2&gt;
&lt;ul&gt;&lt;li&gt;(bug 58640) Fixed a compatibility issue with PCRE 8.34 that caused pages
to appear blank or with missing text.
&lt;/li&gt;&lt;/ul&gt;&lt;p&gt;
Full release notes for 1.22.6:
&lt;a class="ext-link" href="https://www.mediawiki.org/wiki/Release_notes/1.22"&gt;&lt;span class="icon"&gt;​&lt;/span&gt;https://www.mediawiki.org/wiki/Release_notes/1.22&lt;/a&gt;
&lt;/p&gt;
&lt;/blockquote&gt;
</description>
        <category>Results</category>
        <comments>http://localhost:8080/trac/ticket/723#changelog</comments>
    </item><item>
        <link>http://localhost:8080/trac/ticket/706</link>
        <guid isPermaLink="false">http://localhost:8080/trac/ticket/706</guid>
        <title>#706: Upgrade Mediawiki to 1.22.5 and install the new VisualEditor</title>
        <pubDate>Wed, 26 Mar 2014 15:46:03 GMT</pubDate>
        
        <dc:creator>chris</dc:creator>

        <description>&lt;p&gt;
From &lt;a class="ext-link" href="http://lists.wikimedia.org/pipermail/mediawiki-announce/2014-March/000144.html"&gt;&lt;span class="icon"&gt;​&lt;/span&gt;MediaWiki-announce&lt;/a&gt;:
&lt;/p&gt;
&lt;blockquote class="citation"&gt;
&lt;p&gt;
this is a notice that on Thursday, March 27th between 17:00-18:00 UTC (Thursday, March 27th, 9:00-10:00am PST) we will release security and maintenance updates for current and supported branches of the &lt;a class="wiki" href="http://localhost:8080/trac/wiki/MediaWiki"&gt;MediaWiki&lt;/a&gt; software. Downloads and patches will be available at that time.
&lt;/p&gt;
&lt;/blockquote&gt;
</description>
        <category>Results</category>
        <comments>http://localhost:8080/trac/ticket/706#changelog</comments>
    </item><item>
        <link>http://localhost:8080/trac/ticket/700</link>
        <guid isPermaLink="false">http://localhost:8080/trac/ticket/700</guid>
        <title>#700: Mediawiki 1.19.13</title>
        <pubDate>Wed, 12 Mar 2014 11:06:44 GMT</pubDate>
        
        <dc:creator>chris</dc:creator>

        <description>&lt;p&gt;
From the &lt;a class="ext-link" href="http://lists.wikimedia.org/pipermail/mediawiki-announce/2014-March/000143.html"&gt;&lt;span class="icon"&gt;​&lt;/span&gt;MediaWiki-announce list&lt;/a&gt;:
&lt;/p&gt;
&lt;blockquote class="citation"&gt;
&lt;p&gt;
I would like to announce the release of &lt;a class="wiki" href="http://localhost:8080/trac/wiki/MediaWiki"&gt;MediaWiki&lt;/a&gt; 1.22.4, 1.21.7 and 1.19.13.  Other than the security fix included in 1.19.13, these releases simply fix the bundled version of the tarball. Download links are given at the end of this email.
&lt;/p&gt;
&lt;h2 id="Securityfixbackportedto1.19"&gt;Security fix backported to 1.19&lt;/h2&gt;
&lt;ul&gt;&lt;li&gt;(bug 61362) SECURITY: API: Don't find links in the middle of api.php links.
&lt;/li&gt;&lt;/ul&gt;&lt;h2 id="Fixesmadeinalltarballs"&gt;Fixes made in all tarballs&lt;/h2&gt;
&lt;ul&gt;&lt;li&gt;The correct branch of each extensions git repository (e.g. REL1_19 for 1.19.13) was used.
&lt;/li&gt;&lt;/ul&gt;&lt;/blockquote&gt;
</description>
        <category>Results</category>
        <comments>http://localhost:8080/trac/ticket/700#changelog</comments>
    </item><item>
        <link>http://localhost:8080/trac/ticket/694</link>
        <guid isPermaLink="false">http://localhost:8080/trac/ticket/694</guid>
        <title>#694: Mediawiki 1.19.12 upgrade</title>
        <pubDate>Fri, 28 Feb 2014 09:03:20 GMT</pubDate>
        
        <dc:creator>chris</dc:creator>

        <description>&lt;p&gt;
On the &lt;a class="ext-link" href="http://lists.wikimedia.org/pipermail/mediawiki-announce/2014-February/000141.html"&gt;&lt;span class="icon"&gt;​&lt;/span&gt;MediaWiki-announce list&lt;/a&gt;:
&lt;/p&gt;
&lt;blockquote class="citation"&gt;
&lt;p&gt;
I would like to announce the release of &lt;a class="wiki" href="http://localhost:8080/trac/wiki/MediaWiki"&gt;MediaWiki&lt;/a&gt; 1.22.3, 1.21.6 and 1.19.12.
These releases fix a number of security related bugs that could affect users
of &lt;a class="wiki" href="http://localhost:8080/trac/wiki/MediaWiki"&gt;MediaWiki&lt;/a&gt;. In addition, &lt;a class="wiki" href="http://localhost:8080/trac/wiki/MediaWiki"&gt;MediaWiki&lt;/a&gt; 1.22.3 is a maintenance release. It fixes
several bugs. You can consult the RELEASE-NOTES-1.22 file for the full list of
changes in this version. Download links are given at the end of this email.
&lt;/p&gt;
&lt;h2 id="Securityfixes"&gt;Security fixes&lt;/h2&gt;
&lt;ul&gt;&lt;li&gt;(bug 60771) SECURITY: Disallow uploading SVG files using non-whitelisted
namespaces. Also disallow iframe elements. User will get an error
including the namespace name if they use a non- whitelisted namespace.
&lt;/li&gt;&lt;li&gt;(bug 61346) SECURITY: Make token comparison use constant time. It seems like
our token comparison would be vulnerable to timing attacks. This will take
constant time.
&lt;/li&gt;&lt;li&gt;(bug 61362) SECURITY: API: Don't find links in the middle of api.php links.
&lt;/li&gt;&lt;/ul&gt;&lt;/blockquote&gt;
</description>
        <category>Results</category>
        <comments>http://localhost:8080/trac/ticket/694#changelog</comments>
    </item><item>
        <link>http://localhost:8080/trac/ticket/686</link>
        <guid isPermaLink="false">http://localhost:8080/trac/ticket/686</guid>
        <title>#686: MediaWiki 1.19.11 Update</title>
        <pubDate>Wed, 29 Jan 2014 09:53:13 GMT</pubDate>
        
        <dc:creator>chris</dc:creator>

        <description>&lt;p&gt;
On the &lt;a class="ext-link" href="http://lists.wikimedia.org/pipermail/mediawiki-announce/2014-January/000140.html"&gt;&lt;span class="icon"&gt;​&lt;/span&gt;MediaWiki-announce list&lt;/a&gt;:
&lt;/p&gt;
&lt;blockquote class="citation"&gt;
&lt;p&gt;
I would like to announce the release of MediaWiki 1.22.2, 1.21.5 and 1.19.11.
&lt;/p&gt;
&lt;p&gt;
Your MediaWiki installation is affected by a remote code execution vulnerability if you have enabled file upload support for DjVu (natively supported by MediaWiki) or PDF files (in combination with the PdfHandlerxtension). Neither file type is enabled by default in MediaWiki installations. If you are affected, we strongly urge you to update immediately.
&lt;/p&gt;
&lt;p&gt;
Affected supported versions: All
&lt;/p&gt;
&lt;h2 id="Securityfixes"&gt;Security fixes&lt;/h2&gt;
&lt;ul&gt;&lt;li&gt;Netanel Rubin from Check Point discovered a remote code execution
vulnerability in MediaWiki's thumbnail generation for DjVu files. Internal
review also discovered similar logic in the PdfHandler extension, which
could be exploited in a similar way. (CVE-2014-1610)
&lt;a class="ext-link" href="https://bugzilla.wikimedia.org/show_bug.cgi?id=60339"&gt;&lt;span class="icon"&gt;​&lt;/span&gt;https://bugzilla.wikimedia.org/show_bug.cgi?id=60339&lt;/a&gt;
&lt;/li&gt;&lt;/ul&gt;&lt;h2 id="BugFixesin1.22.2"&gt;Bug Fixes in 1.22.2&lt;/h2&gt;
&lt;ul&gt;&lt;li&gt;(bug 58253) Check for very old PCRE versions in installer and updater
&lt;/li&gt;&lt;li&gt;(bug 60054) Make WikiPage::$mPreparedEdit public
&lt;/li&gt;&lt;/ul&gt;&lt;p&gt;
Full release notes for 1.19.9:
&lt;/p&gt;
&lt;ul&gt;&lt;li&gt;&lt;a class="ext-link" href="https://www.mediawiki.org/wiki/Release_notes/1.19"&gt;&lt;span class="icon"&gt;​&lt;/span&gt;https://www.mediawiki.org/wiki/Release_notes/1.19&lt;/a&gt;
&lt;/li&gt;&lt;/ul&gt;&lt;/blockquote&gt;
</description>
        <category>Results</category>
        <comments>http://localhost:8080/trac/ticket/686#changelog</comments>
    </item><item>
        <link>http://localhost:8080/trac/ticket/669</link>
        <guid isPermaLink="false">http://localhost:8080/trac/ticket/669</guid>
        <title>#669: Mediawiki upgrade to 1.19.10</title>
        <pubDate>Sat, 11 Jan 2014 09:00:24 GMT</pubDate>
        
        <dc:creator>chris</dc:creator>

        <description>&lt;p&gt;
Email from Mediawiki:
&lt;/p&gt;
&lt;blockquote class="citation"&gt;
&lt;p&gt;
This is a notice that on Tuesday, January 14th between 00:00-01:00 UTC (*Monday* January 13th, 4-5pm PST) Wikimedia Foundation will release security updates for current and supported branches of the &lt;a class="wiki" href="http://localhost:8080/trac/wiki/MediaWiki"&gt;MediaWiki&lt;/a&gt; software, as well as several extensions. Downloads and patches will be available at that time.
&lt;/p&gt;
&lt;/blockquote&gt;
</description>
        <category>Results</category>
        <comments>http://localhost:8080/trac/ticket/669#changelog</comments>
    </item><item>
        <link>http://localhost:8080/trac/ticket/620</link>
        <guid isPermaLink="false">http://localhost:8080/trac/ticket/620</guid>
        <title>#620: Upgrade MediaWiki to 1.19.9</title>
        <pubDate>Fri, 15 Nov 2013 14:57:58 GMT</pubDate>
        
        <dc:creator>chris</dc:creator>

        <description>&lt;p&gt;
See the announcement email:
&lt;/p&gt;
&lt;pre class="wiki"&gt;I would like to announce the release of MediaWiki 1.21.3, 1.20.8 and
1.19.9. These releases fix 2 security related bugs that could affect users
of MediaWiki. Download links are given at the end of this email.
* Kevin Israel (Wikipedia user PleaseStand) identified and reported two
vectors for injecting Javascript in CSS that bypassed MediaWiki's blacklist
(CVE-2013-4567, CVE-2013-4568).
&amp;lt;https://bugzilla.wikimedia.org/show_bug.cgi?id=55332&amp;gt;
* Internal review while debugging a site issue discovered that MediaWiki
and the CentralNotice extension were incorrectly setting cache headers when
a user was autocreated, causing the user's session cookies to be cached,
and returned to other users (CVE-2013-4572).
&amp;lt;https://bugzilla.wikimedia.org/show_bug.cgi?id=53032&amp;gt;
Additionally, the following extensions have been updated to fix security
issues:
* CleanChanges: MediaWiki steward Teles reported that revision-deleted IP's
are not correctly hidden when this extension is used (CVE-2013-4569).
&amp;lt;https://bugzilla.wikimedia.org/show_bug.cgi?id=54294&amp;gt;
* ZeroRatedMobileAccess: Tomasz Chlebowski reported an XSS vulnerability
(CVE-2013-4573).
&amp;lt;https://bugzilla.wikimedia.org/show_bug.cgi?id=55991&amp;gt;
* CentralAuth: MediaWiki developer Platonides reported a login CSRF in
CentralAuth (CVE-2012-5394).
&amp;lt;https://bugzilla.wikimedia.org/show_bug.cgi?id=40747&amp;gt;
Full release notes for 1.21.3:
&amp;lt;https://www.mediawiki.org/wiki/Release_notes/1.21&amp;gt;
Full release notes for 1.20.8:
&amp;lt;https://www.mediawiki.org/wiki/Release_notes/1.20&amp;gt;
Full release notes for 1.19.9:
&amp;lt;https://www.mediawiki.org/wiki/Release_notes/1.19&amp;gt;
For information about how to upgrade, see
&amp;lt;https://www.mediawiki.org/wiki/Manual:Upgrading&amp;gt;
&lt;/pre&gt;&lt;p&gt;
The steps followed for the last upgrade can be followed again, see &lt;a class="closed ticket" href="http://localhost:8080/trac/ticket/595" title="maintenance: Upgrade Mediawiki to 1.19.8 from 1.19.7 (closed: fixed)"&gt;ticket:595&lt;/a&gt; and see also the documentation at &lt;a class="wiki" href="http://localhost:8080/trac/wiki/PenguinServer#wiki.transitionnetwork.org"&gt;wiki:PenguinServer#wiki.transitionnetwork.org&lt;/a&gt;
&lt;/p&gt;
</description>
        <category>Results</category>
        <comments>http://localhost:8080/trac/ticket/620#changelog</comments>
    </item><item>
        <link>http://localhost:8080/trac/ticket/595</link>
        <guid isPermaLink="false">http://localhost:8080/trac/ticket/595</guid>
        <title>#595: Upgrade Mediawiki to 1.19.8 from 1.19.7</title>
        <pubDate>Wed, 11 Sep 2013 22:18:05 GMT</pubDate>
        
        <dc:creator>chris</dc:creator>

        <description>&lt;p&gt;
From &lt;a class="ext-link" href="https://git.wikimedia.org/blob/mediawiki%2Fcore.git/REL1_19/RELEASE-NOTES-1.19"&gt;&lt;span class="icon"&gt;​&lt;/span&gt;https://git.wikimedia.org/blob/mediawiki%2Fcore.git/REL1_19/RELEASE-NOTES-1.19&lt;/a&gt;
&lt;/p&gt;
&lt;blockquote class="citation"&gt;
&lt;h2 id="MediaWiki1.19.8"&gt;MediaWiki 1.19.8&lt;/h2&gt;
&lt;p&gt;
This is a security and maintenance release of the MediaWiki 1.19 branch.
&lt;/p&gt;
&lt;h3 id="Changessince1.19.7"&gt;Changes since 1.19.7&lt;/h3&gt;
&lt;ul&gt;&lt;li&gt;SECURITY: Sanitize ResourceLoader exception messages
&lt;/li&gt;&lt;li&gt;SECURITY: Token-getting functions will fail when using jsonp callbacks.
&lt;/li&gt;&lt;li&gt;SECURITY: Fix extension detection with 2 .'s
&lt;/li&gt;&lt;li&gt;Allow a string other than '*' as condition for DatabaseBase::delete()
&lt;/li&gt;&lt;li&gt;Purge upstream caches when deleting file assets.
&lt;/li&gt;&lt;li&gt;jquery.tablesorter: Add missing dependency on jquery.mwExtension
&lt;/li&gt;&lt;/ul&gt;&lt;/blockquote&gt;
</description>
        <category>Results</category>
        <comments>http://localhost:8080/trac/ticket/595#changelog</comments>
    </item><item>
        <link>http://localhost:8080/trac/ticket/551</link>
        <guid isPermaLink="false">http://localhost:8080/trac/ticket/551</guid>
        <title>#551: Mediawiki 1.19.7 upgrade</title>
        <pubDate>Tue, 21 May 2013 08:25:51 GMT</pubDate>
        
        <dc:creator>chris</dc:creator>

        <description>&lt;p&gt;
From &lt;a class="ext-link" href="http://lists.wikimedia.org/pipermail/mediawiki-announce/2013-May/000130.html"&gt;&lt;span class="icon"&gt;​&lt;/span&gt;MediaWiki-announce&lt;/a&gt;:
&lt;/p&gt;
&lt;blockquote class="citation"&gt;
&lt;p&gt;
This is a notice that on Tuesday, May 21st between 20:00-21:00 UTC
(1-2pm PDT) Wikimedia Foundation will release security updates for
current and supported branches of the MediaWiki software. Downloads
and patches will be available at that time, with the git repositories
updated later that afternoon. Although &lt;strong&gt;MediaWiki does not have the&lt;/strong&gt;
&lt;strong&gt;vulnerable feature enabled by default&lt;/strong&gt;, most wiki using common advanced
features will want to patch for this issue.
&lt;/p&gt;
&lt;/blockquote&gt;
</description>
        <category>Results</category>
        <comments>http://localhost:8080/trac/ticket/551#changelog</comments>
    </item><item>
        <link>http://localhost:8080/trac/ticket/536</link>
        <guid isPermaLink="false">http://localhost:8080/trac/ticket/536</guid>
        <title>#536: Upgrade Mediawiki to 1.19.6</title>
        <pubDate>Mon, 29 Apr 2013 20:35:32 GMT</pubDate>
        
        <dc:creator>chris</dc:creator>

        <description>&lt;p&gt;
A new version of Mediawiki is due out tomorrow:
&lt;/p&gt;
&lt;blockquote class="citation"&gt;
&lt;p&gt;
This is a notice that on Tuesday, April 30th between 20:00-21:00 UTC
(1-2pm PDT) Wikimedia Foundation will release security updates for
current and supported branches of the &lt;a class="wiki" href="http://localhost:8080/trac/wiki/MediaWiki"&gt;MediaWiki&lt;/a&gt; software. Downloads
and patches will be available at that time, with the git repositories
updated later that afternoon.
&lt;/p&gt;
&lt;p&gt;
&lt;a class="ext-link" href="http://lists.wikimedia.org/pipermail/mediawiki-announce/2013-April/000128.html"&gt;&lt;span class="icon"&gt;​&lt;/span&gt;http://lists.wikimedia.org/pipermail/mediawiki-announce/2013-April/000128.html&lt;/a&gt;
&lt;/p&gt;
&lt;/blockquote&gt;
&lt;p&gt;
The upgrade should simply be a matter of following the steps taken last time, see &lt;a class="closed ticket" href="http://localhost:8080/trac/ticket/532#comment:2" title="maintenance: Upgrade to Mediawiki 1.19.5 (closed: fixed)"&gt;ticket:532#comment:2&lt;/a&gt;
&lt;/p&gt;
</description>
        <category>Results</category>
        <comments>http://localhost:8080/trac/ticket/536#changelog</comments>
    </item><item>
        <link>http://localhost:8080/trac/ticket/532</link>
        <guid isPermaLink="false">http://localhost:8080/trac/ticket/532</guid>
        <title>#532: Upgrade to Mediawiki 1.19.5</title>
        <pubDate>Mon, 15 Apr 2013 13:40:34 GMT</pubDate>
        
        <dc:creator>chris</dc:creator>

        <description>&lt;p&gt;
New version out tonight:
&lt;/p&gt;
&lt;blockquote class="citation"&gt;
&lt;p&gt;
This is a notice that on Monday, April 15th between 20:00-21:00 UTC
(1-2pm PDT) Wikimedia Foundation will release security updates for
current and supported branches of the MediaWiki software. Downloads
and patches will be available at that time, with the git repositories
updated later that afternoon. CVSS scores are between 4.3 and 7.1,
most users will want to update.
&lt;/p&gt;
&lt;p&gt;
&lt;a class="ext-link" href="http://lists.wikimedia.org/pipermail/mediawiki-announce/2013-April/000126.html"&gt;&lt;span class="icon"&gt;​&lt;/span&gt;http://lists.wikimedia.org/pipermail/mediawiki-announce/2013-April/000126.html&lt;/a&gt;
&lt;/p&gt;
&lt;/blockquote&gt;
</description>
        <category>Results</category>
        <comments>http://localhost:8080/trac/ticket/532#changelog</comments>
    </item>
 </channel>
</rss>