<?xml version="1.0"?>
<rss xmlns:dc="http://purl.org/dc/elements/1.1/" version="2.0">
  <channel>
    <title>Transition Technology: Ticket #620: Upgrade MediaWiki to 1.19.9</title>
    <link>http://localhost:8080/trac/ticket/620</link>
    <description>&lt;p&gt;
See the announcement email:
&lt;/p&gt;
&lt;pre class="wiki"&gt;I would like to announce the release of MediaWiki 1.21.3, 1.20.8 and
1.19.9. These releases fix 2 security related bugs that could affect users
of MediaWiki. Download links are given at the end of this email.
* Kevin Israel (Wikipedia user PleaseStand) identified and reported two
vectors for injecting Javascript in CSS that bypassed MediaWiki's blacklist
(CVE-2013-4567, CVE-2013-4568).
&amp;lt;https://bugzilla.wikimedia.org/show_bug.cgi?id=55332&amp;gt;
* Internal review while debugging a site issue discovered that MediaWiki
and the CentralNotice extension were incorrectly setting cache headers when
a user was autocreated, causing the user's session cookies to be cached,
and returned to other users (CVE-2013-4572).
&amp;lt;https://bugzilla.wikimedia.org/show_bug.cgi?id=53032&amp;gt;
Additionally, the following extensions have been updated to fix security
issues:
* CleanChanges: MediaWiki steward Teles reported that revision-deleted IP's
are not correctly hidden when this extension is used (CVE-2013-4569).
&amp;lt;https://bugzilla.wikimedia.org/show_bug.cgi?id=54294&amp;gt;
* ZeroRatedMobileAccess: Tomasz Chlebowski reported an XSS vulnerability
(CVE-2013-4573).
&amp;lt;https://bugzilla.wikimedia.org/show_bug.cgi?id=55991&amp;gt;
* CentralAuth: MediaWiki developer Platonides reported a login CSRF in
CentralAuth (CVE-2012-5394).
&amp;lt;https://bugzilla.wikimedia.org/show_bug.cgi?id=40747&amp;gt;
Full release notes for 1.21.3:
&amp;lt;https://www.mediawiki.org/wiki/Release_notes/1.21&amp;gt;
Full release notes for 1.20.8:
&amp;lt;https://www.mediawiki.org/wiki/Release_notes/1.20&amp;gt;
Full release notes for 1.19.9:
&amp;lt;https://www.mediawiki.org/wiki/Release_notes/1.19&amp;gt;
For information about how to upgrade, see
&amp;lt;https://www.mediawiki.org/wiki/Manual:Upgrading&amp;gt;
&lt;/pre&gt;&lt;p&gt;
The steps followed for the last upgrade can be followed again, see &lt;a class="closed ticket" href="http://localhost:8080/trac/ticket/595" title="maintenance: Upgrade Mediawiki to 1.19.8 from 1.19.7 (closed: fixed)"&gt;ticket:595&lt;/a&gt; and see also the documentation at &lt;a class="wiki" href="http://localhost:8080/trac/wiki/PenguinServer#wiki.transitionnetwork.org"&gt;wiki:PenguinServer#wiki.transitionnetwork.org&lt;/a&gt;
&lt;/p&gt;
</description>
    <language>en-us</language>
    <image>
      <title>Transition Technology</title>
      <url>/trac/chrome/site/TransitionNetwork-Logo-Web-Small.jpg</url>
      <link>http://localhost:8080/trac/ticket/620</link>
    </image>
    <generator>Trac 0.12.5</generator>
    <item>
      
        <dc:creator>chris</dc:creator>

      <pubDate>Thu, 21 Nov 2013 10:31:10 GMT</pubDate>
      <title>hours, status, totalhours changed; resolution set</title>
      <link>http://localhost:8080/trac/ticket/620#comment:1</link>
      <guid isPermaLink="false">http://localhost:8080/trac/ticket/620#comment:1</guid>
      <description>
          &lt;ul&gt;
            &lt;li&gt;&lt;strong&gt;hours&lt;/strong&gt;
                changed from &lt;em&gt;0.0&lt;/em&gt; to &lt;em&gt;0.25&lt;/em&gt;
            &lt;/li&gt;
            &lt;li&gt;&lt;strong&gt;status&lt;/strong&gt;
                changed from &lt;em&gt;new&lt;/em&gt; to &lt;em&gt;closed&lt;/em&gt;
            &lt;/li&gt;
            &lt;li&gt;&lt;strong&gt;resolution&lt;/strong&gt;
                set to &lt;em&gt;fixed&lt;/em&gt;
            &lt;/li&gt;
            &lt;li&gt;&lt;strong&gt;totalhours&lt;/strong&gt;
                changed from &lt;em&gt;0.0&lt;/em&gt; to &lt;em&gt;0.25&lt;/em&gt;
            &lt;/li&gt;
          &lt;/ul&gt;
        &lt;p&gt;
Following the last upgrade, &lt;a class="closed ticket" href="http://localhost:8080/trac/ticket/595#comment:1" title="maintenance: Upgrade Mediawiki to 1.19.8 from 1.19.7 (closed: fixed)"&gt;ticket:595#comment:1&lt;/a&gt;
&lt;/p&gt;
&lt;pre class="wiki"&gt;sudo -i
cd /web/wiki.transitionnetwork.org
export MW="1.19.9"
wget http://download.wikimedia.org/mediawiki/1.19/mediawiki-$MW.tar.gz
wget http://download.wikimedia.org/mediawiki/1.19/mediawiki-$MW.tar.gz.sig
gpg --verify mediawiki-$MW.tar.gz.sig
tar -zxvf mediawiki-$MW.tar.gz
rsync -av mediawiki-$MW/ www/
chown root:root -R www/
chown -R www-data:www-data www/cache
chown -R www-data:www-data www/images
cd www/maintenance/
php update.php
&lt;/pre&gt;&lt;p&gt;
The version was checked: &lt;a class="ext-link" href="http://wiki.transitionnetwork.org/Special:Version"&gt;&lt;span class="icon"&gt;​&lt;/span&gt;http://wiki.transitionnetwork.org/Special:Version&lt;/a&gt; and everthing seems fine, so closing this ticket.
&lt;/p&gt;
      </description>
      <category>Ticket</category>
    </item>
 </channel>
</rss>