Ticket #694 (closed maintenance: fixed)
Mediawiki 1.19.12 upgrade
Reported by: | chris | Owned by: | chris |
---|---|---|---|
Priority: | major | Milestone: | Maintenance |
Component: | Mediawiki | Keywords: | |
Cc: | ed | Estimated Number of Hours: | 0.0 |
Add Hours to Ticket: | 0 | Billable?: | yes |
Total Hours: | 0.25 |
Description
On the MediaWiki-announce list:
I would like to announce the release of MediaWiki 1.22.3, 1.21.6 and 1.19.12.
These releases fix a number of security related bugs that could affect users
of MediaWiki. In addition, MediaWiki 1.22.3 is a maintenance release. It fixes
several bugs. You can consult the RELEASE-NOTES-1.22 file for the full list of
changes in this version. Download links are given at the end of this email.
Security fixes
- (bug 60771) SECURITY: Disallow uploading SVG files using non-whitelisted namespaces. Also disallow iframe elements. User will get an error including the namespace name if they use a non- whitelisted namespace.
- (bug 61346) SECURITY: Make token comparison use constant time. It seems like our token comparison would be vulnerable to timing attacks. This will take constant time.
- (bug 61362) SECURITY: API: Don't find links in the middle of api.php links.
Change History
Note: See
TracTickets for help on using
tickets.
Following the notes from the last upgrade, ticket:686
The version was checked: http://wiki.transitionnetwork.org/Special:Version and everthing seems fine.
The wiki:MediaWiki documentation was updated to reflect the new download URL.