<?xml version="1.0"?>
<rss xmlns:dc="http://purl.org/dc/elements/1.1/" version="2.0">
  <channel>
    <title>Transition Technology: Ticket #506: Mediawiki 1.19.4 Upgrade</title>
    <link>http://localhost:8080/trac/ticket/506</link>
    <description>&lt;p&gt;
Announcement:
&lt;/p&gt;
&lt;blockquote class="citation"&gt;
&lt;p&gt;
I would like to announce the release of MediaWiki 1.20.3 and 1.19.4.  These releases fix 3 security related bugs that could affect users of MediaWiki. Download links are given at the end of this email.
&lt;/p&gt;
&lt;ul&gt;&lt;li&gt;By default, the curl library passed 'true' to CURLOPT_SSL_VERIFYHOST when establishing an SSL connection, instead of '2'.  &lt;a class="ext-link" href="https://bugzilla.wikimedia.org/show_bug.cgi?id=44135"&gt;&lt;span class="icon"&gt;​&lt;/span&gt;https://bugzilla.wikimedia.org/show_bug.cgi?id=44135&lt;/a&gt; &lt;a class="ext-link" href="https://bugzilla.wikimedia.org/show_bug.cgi?id=42441"&gt;&lt;span class="icon"&gt;​&lt;/span&gt;https://bugzilla.wikimedia.org/show_bug.cgi?id=42441&lt;/a&gt;
&lt;/li&gt;&lt;/ul&gt;&lt;ul&gt;&lt;li&gt;MediaWiki developer Krenair discovered that the full user object, including password hash, could be returned when unblocking a user by the API. Exploitation of this vulnerability requires the user to have permissions to unblock users, by default this is limited to users in the sysop group.  &lt;a class="ext-link" href="https://bugzilla.wikimedia.org/show_bug.cgi?id=43518"&gt;&lt;span class="icon"&gt;​&lt;/span&gt;https://bugzilla.wikimedia.org/show_bug.cgi?id=43518&lt;/a&gt;
&lt;/li&gt;&lt;/ul&gt;&lt;ul&gt;&lt;li&gt;MediaWiki developer Platonides discovered that the maintenance script mwdoc-filter.php did not check if it was being run via the CLI, and could allow an attacker to read arbitrary files if PHP's register_globals was enabled and the .htaccess file in the maintenance directory, which by default denies access for all users, was disabled.  &lt;a class="ext-link" href="https://bugzilla.wikimedia.org/show_bug.cgi?id=45355"&gt;&lt;span class="icon"&gt;​&lt;/span&gt;https://bugzilla.wikimedia.org/show_bug.cgi?id=45355&lt;/a&gt;
&lt;/li&gt;&lt;/ul&gt;&lt;p&gt;
Full release notes for 1.19.4: &lt;a class="ext-link" href="https://www.mediawiki.org/wiki/Release_notes/1.19"&gt;&lt;span class="icon"&gt;​&lt;/span&gt;https://www.mediawiki.org/wiki/Release_notes/1.19&lt;/a&gt;
&lt;/p&gt;
&lt;/blockquote&gt;
&lt;p&gt;
&lt;a class="ext-link" href="http://lists.wikimedia.org/pipermail/mediawiki-announce/2013-March/000125.html"&gt;&lt;span class="icon"&gt;​&lt;/span&gt;http://lists.wikimedia.org/pipermail/mediawiki-announce/2013-March/000125.html&lt;/a&gt;
&lt;/p&gt;
</description>
    <language>en-us</language>
    <image>
      <title>Transition Technology</title>
      <url>/trac/chrome/site/TransitionNetwork-Logo-Web-Small.jpg</url>
      <link>http://localhost:8080/trac/ticket/506</link>
    </image>
    <generator>Trac 0.12.5</generator>
    <item>
      
        <dc:creator>chris</dc:creator>

      <pubDate>Mon, 04 Mar 2013 19:47:57 GMT</pubDate>
      <title>hours, totalhours changed</title>
      <link>http://localhost:8080/trac/ticket/506#comment:1</link>
      <guid isPermaLink="false">http://localhost:8080/trac/ticket/506#comment:1</guid>
      <description>
          &lt;ul&gt;
            &lt;li&gt;&lt;strong&gt;hours&lt;/strong&gt;
                changed from &lt;em&gt;0.0&lt;/em&gt; to &lt;em&gt;0.1&lt;/em&gt;
            &lt;/li&gt;
            &lt;li&gt;&lt;strong&gt;totalhours&lt;/strong&gt;
                changed from &lt;em&gt;0.0&lt;/em&gt; to &lt;em&gt;0.1&lt;/em&gt;
            &lt;/li&gt;
          &lt;/ul&gt;
      </description>
      <category>Ticket</category>
    </item><item>
      
        <dc:creator>chris</dc:creator>

      <pubDate>Mon, 04 Mar 2013 20:05:45 GMT</pubDate>
      <title>hours, totalhours changed</title>
      <link>http://localhost:8080/trac/ticket/506#comment:2</link>
      <guid isPermaLink="false">http://localhost:8080/trac/ticket/506#comment:2</guid>
      <description>
          &lt;ul&gt;
            &lt;li&gt;&lt;strong&gt;hours&lt;/strong&gt;
                changed from &lt;em&gt;0.0&lt;/em&gt; to &lt;em&gt;0.25&lt;/em&gt;
            &lt;/li&gt;
            &lt;li&gt;&lt;strong&gt;totalhours&lt;/strong&gt;
                changed from &lt;em&gt;0.1&lt;/em&gt; to &lt;em&gt;0.35&lt;/em&gt;
            &lt;/li&gt;
          &lt;/ul&gt;
        &lt;p&gt;
Following the last upgrade, &lt;a class="closed ticket" href="http://localhost:8080/trac/ticket/470#comment:11" title="maintenance: Penguin install and configuration (closed: fixed)"&gt;ticket:470#comment:11&lt;/a&gt;
&lt;/p&gt;
&lt;pre class="wiki"&gt;cd /web/wiki.transitionnetwork.org/
wget http://download.wikimedia.org/mediawiki/1.19/mediawiki-1.19.4.tar.gz
wget http://download.wikimedia.org/mediawiki/1.19/mediawiki-1.19.4.tar.gz.sig
gpg --verify mediawiki-1.19.4.tar.gz.sig
 gpg: Signature made Mon Mar  4 18:12:00 2013 GMT using DSA key ID 62D84F01
 gpg: Good signature from "Chris Steipp &amp;lt;csteipp@wikimedia.org&amp;gt;"
tar -zxvf mediawiki-1.19.4.tar.gz
rsync -av mediawiki-1.19.4/ www/
cd www/maintenance/
php update.php
cd ..
chown root:root -R www/
cd www
chown -R www-data:www-data cache
chown -R www-data:www-data images
&lt;/pre&gt;&lt;p&gt;
And now we are running the latest version of 1.19: &lt;a class="ext-link" href="https://wiki.transitionnetwork.org/Special:Version"&gt;&lt;span class="icon"&gt;​&lt;/span&gt;https://wiki.transitionnetwork.org/Special:Version&lt;/a&gt; and the docs have been updated, &lt;a class="wiki" href="http://localhost:8080/trac/wiki/PenguinServer#wiki.transitionnetwork.org"&gt;wiki:PenguinServer#wiki.transitionnetwork.org&lt;/a&gt; and also the duplicate ticket has been closed, &lt;a class="closed ticket" href="http://localhost:8080/trac/ticket/505" title="maintenance: Critical Mediawiki security upgrade (closed: fixed)"&gt;ticket:505&lt;/a&gt;
&lt;/p&gt;
      </description>
      <category>Ticket</category>
    </item><item>
      
        <dc:creator>chris</dc:creator>

      <pubDate>Mon, 04 Mar 2013 20:06:09 GMT</pubDate>
      <title>status changed; resolution set</title>
      <link>http://localhost:8080/trac/ticket/506#comment:3</link>
      <guid isPermaLink="false">http://localhost:8080/trac/ticket/506#comment:3</guid>
      <description>
          &lt;ul&gt;
            &lt;li&gt;&lt;strong&gt;status&lt;/strong&gt;
                changed from &lt;em&gt;new&lt;/em&gt; to &lt;em&gt;closed&lt;/em&gt;
            &lt;/li&gt;
            &lt;li&gt;&lt;strong&gt;resolution&lt;/strong&gt;
                set to &lt;em&gt;fixed&lt;/em&gt;
            &lt;/li&gt;
          &lt;/ul&gt;
      </description>
      <category>Ticket</category>
    </item>
 </channel>
</rss>