<?xml version="1.0"?>
<rss xmlns:dc="http://purl.org/dc/elements/1.1/" version="2.0">
  <channel>
    <title>Transition Technology: Ticket #813: MediaWiki 1.23.7</title>
    <link>http://localhost:8080/trac/ticket/813</link>
    <description>&lt;p&gt;
The &lt;a class="ext-link" href="https://lists.wikimedia.org/pipermail/mediawiki-announce/2014-November/000170.html"&gt;&lt;span class="icon"&gt;​&lt;/span&gt;announcement email&lt;/a&gt;:
&lt;/p&gt;
&lt;p&gt;
I would like to announce the release of &lt;a class="wiki" href="http://localhost:8080/trac/wiki/MediaWiki"&gt;MediaWiki&lt;/a&gt; 1.23.7, 1.22.14 and 1.19.22. This is a regular security and maintenance release. Download links are given at the end of this email.
&lt;/p&gt;
&lt;blockquote class="citation"&gt;
&lt;h2 id="Securityfixes"&gt;Security fixes&lt;/h2&gt;
&lt;ul&gt;&lt;li&gt;(bugs 66776, 71478) SECURITY:  User PleaseStand reported a way to inject code into API clients that used format=php to process pages that underwent flash policy mangling. This was fixed along with improving how the mangling was done for format=json, and allowing sites to disable the mangling using $wgMangleFlashPolicy.  &lt;a class="ext-link" href="https://phabricator.wikimedia.org/T68776"&gt;&lt;span class="icon"&gt;​&lt;/span&gt;https://phabricator.wikimedia.org/T68776&lt;/a&gt; &lt;a class="ext-link" href="https://phabricator.wikimedia.org/T73478"&gt;&lt;span class="icon"&gt;​&lt;/span&gt;https://phabricator.wikimedia.org/T73478&lt;/a&gt;
&lt;/li&gt;&lt;/ul&gt;&lt;ul&gt;&lt;li&gt;(bug 70901) SECURITY: User Jackmcbarn reported that the ability to update the content model for a page could allow an unprivileged attacker to edit another user's common.js under certain circumstances. The user right "editcontentmodel" was added, and is needed to change a revision's content model.  &lt;a class="ext-link" href="https://phabricator.wikimedia.org/T72901"&gt;&lt;span class="icon"&gt;​&lt;/span&gt;https://phabricator.wikimedia.org/T72901&lt;/a&gt;
&lt;/li&gt;&lt;/ul&gt;&lt;ul&gt;&lt;li&gt;(bug 71111) SECURITY: User PleaseStand reported that on wikis that allow raw HTML, it is not safe to preview wikitext coming from an untrusted source such as a cross-site request. Thus add an edit token to the form, and when raw HTML is allowed, ensure the token is provided before showing the preview.  This check is not performed on wikis that both allow raw HTML and anonymous editing, since there are easier ways to exploit that scenario.  &lt;a class="ext-link" href="https://phabricator.wikimedia.org/T73111"&gt;&lt;span class="icon"&gt;​&lt;/span&gt;https://phabricator.wikimedia.org/T73111&lt;/a&gt;
&lt;/li&gt;&lt;/ul&gt;&lt;ul&gt;&lt;li&gt;(bug 72222) SECURITY: Do not show log action when the entry is revdeleted with DELETED_ACTION. NOTICE: this may be reverted in a future release pending a public RFC about the desired functionality. This issue was reported by user Bawolff.  &lt;a class="ext-link" href="https://phabricator.wikimedia.org/T74222"&gt;&lt;span class="icon"&gt;​&lt;/span&gt;https://phabricator.wikimedia.org/T74222&lt;/a&gt;
&lt;/li&gt;&lt;/ul&gt;&lt;h2 id="Bugfixes"&gt;Bugfixes&lt;/h2&gt;
&lt;ul&gt;&lt;li&gt;(bug 71621) Make allowing site-wide styles on restricted special pages a config option. &lt;a class="ext-link" href="https://phabricator.wikimedia.org/T73621"&gt;&lt;span class="icon"&gt;​&lt;/span&gt;https://phabricator.wikimedia.org/T73621&lt;/a&gt;
&lt;/li&gt;&lt;/ul&gt;&lt;ul&gt;&lt;li&gt;(bug 42723) Added updated version history from 1.19.2 to 1.22.13 &lt;a class="ext-link" href="https://phabricator.wikimedia.org/T44723"&gt;&lt;span class="icon"&gt;​&lt;/span&gt;https://phabricator.wikimedia.org/T44723&lt;/a&gt;
&lt;/li&gt;&lt;/ul&gt;&lt;ul&gt;&lt;li&gt;$wgMangleFlashPolicy was added to make &lt;a class="wiki" href="http://localhost:8080/trac/wiki/MediaWiki"&gt;MediaWiki&lt;/a&gt;'s mangling of anything that might be a flash policy directive configurable.
&lt;/li&gt;&lt;/ul&gt;&lt;p&gt;
Full release notes for 1.23.7:
&lt;a class="ext-link" href="https://www.mediawiki.org/wiki/Release_notes/1.23"&gt;&lt;span class="icon"&gt;​&lt;/span&gt;https://www.mediawiki.org/wiki/Release_notes/1.23&lt;/a&gt;
&lt;/p&gt;
&lt;/blockquote&gt;
</description>
    <language>en-us</language>
    <image>
      <title>Transition Technology</title>
      <url>/trac/chrome/site/TransitionNetwork-Logo-Web-Small.jpg</url>
      <link>http://localhost:8080/trac/ticket/813</link>
    </image>
    <generator>Trac 0.12.5</generator>
    <item>
      
        <dc:creator>chris</dc:creator>

      <pubDate>Thu, 27 Nov 2014 14:55:07 GMT</pubDate>
      <title>hours, status, totalhours changed; resolution set</title>
      <link>http://localhost:8080/trac/ticket/813#comment:1</link>
      <guid isPermaLink="false">http://localhost:8080/trac/ticket/813#comment:1</guid>
      <description>
          &lt;ul&gt;
            &lt;li&gt;&lt;strong&gt;hours&lt;/strong&gt;
                changed from &lt;em&gt;0.0&lt;/em&gt; to &lt;em&gt;0.25&lt;/em&gt;
            &lt;/li&gt;
            &lt;li&gt;&lt;strong&gt;status&lt;/strong&gt;
                changed from &lt;em&gt;new&lt;/em&gt; to &lt;em&gt;closed&lt;/em&gt;
            &lt;/li&gt;
            &lt;li&gt;&lt;strong&gt;resolution&lt;/strong&gt;
                set to &lt;em&gt;fixed&lt;/em&gt;
            &lt;/li&gt;
            &lt;li&gt;&lt;strong&gt;totalhours&lt;/strong&gt;
                changed from &lt;em&gt;0.0&lt;/em&gt; to &lt;em&gt;0.25&lt;/em&gt;
            &lt;/li&gt;
          &lt;/ul&gt;
        &lt;p&gt;
Following the &lt;a class="wiki" href="http://localhost:8080/trac/wiki/MediaWiki#Updates"&gt;wiki:MediaWiki#Updates&lt;/a&gt; notes:
&lt;/p&gt;
&lt;pre class="wiki"&gt;sudo -i
cd /web/wiki.transitionnetwork.org
export MW="1.23.7"
wget http://releases.wikimedia.org/mediawiki/1.23/mediawiki-$MW.tar.gz -O mediawiki-$MW.tar.gz
wget http://releases.wikimedia.org/mediawiki/1.23/mediawiki-$MW.tar.gz.sig -O mediawiki-$MW.tar.gz.sig
gpg --verify mediawiki-$MW.tar.gz.sig
tar -zxvf mediawiki-$MW.tar.gz
rsync -av mediawiki-$MW/ www/
chown root:root -R www/
chown -R www-data:www-data www/cache/
chown -R www-data:www-data www/images/
cd www/maintenance/
php update.php
cd /web/wiki.transitionnetwork.org
rm mediawiki-$MW.tar.gz mediawiki-$MW.tar.gz.sig
rm -rf mediawiki-$MW
&lt;/pre&gt;&lt;p&gt;
Checked ​&lt;a class="ext-link" href="https://wiki.transitionnetwork.org/Special:Version"&gt;&lt;span class="icon"&gt;​&lt;/span&gt;https://wiki.transitionnetwork.org/Special:Version&lt;/a&gt;
&lt;/p&gt;
      </description>
      <category>Ticket</category>
    </item>
 </channel>
</rss>