<?xml version="1.0"?>
<rss xmlns:dc="http://purl.org/dc/elements/1.1/" version="2.0">
  <channel>
    <title>Transition Technology: Ticket #816: MediaWiki 1.23.8</title>
    <link>http://localhost:8080/trac/ticket/816</link>
    <description>&lt;p&gt;
The &lt;a class="ext-link" href="https://lists.wikimedia.org/pipermail/mediawiki-announce/2014-December/000173.html"&gt;&lt;span class="icon"&gt;​&lt;/span&gt;announcement email&lt;/a&gt;:
&lt;/p&gt;
&lt;blockquote class="citation"&gt;
&lt;p&gt;
I would like to announce the release of &lt;a class="wiki" href="http://localhost:8080/trac/wiki/MediaWiki"&gt;MediaWiki&lt;/a&gt; 1.24.1, 1.23.8, 1.22.15 and 1.19.23. This is a regular security and maintenance release. Download links are given at the end of this email. Please note this release marks the end of lifetime for &lt;a class="wiki" href="http://localhost:8080/trac/wiki/MediaWiki"&gt;MediaWiki&lt;/a&gt; 1.22 branch.
&lt;/p&gt;
&lt;h2 id="Securityfixesin1.24.11.23.81.22.15and1.19.23"&gt;Security fixes in 1.24.1, 1.23.8, 1.22.15 and 1.19.23&lt;/h2&gt;
&lt;ul&gt;&lt;li&gt;(bug T76686) [SECURITY] thumb.php outputs wikitext message as raw HTML,
which could lead to xss. Permission to edit &lt;a class="wiki" href="http://localhost:8080/trac/wiki/MediaWiki"&gt;MediaWiki&lt;/a&gt; namespace is required
to exploit this.
&lt;/li&gt;&lt;li&gt;(bug T77028) [SECURITY] Malicious site can bypass CORS restrictions in
$wgCrossSiteAJAXdomains in API calls if it only included an allowed domain as
part of its name.
&lt;/li&gt;&lt;/ul&gt;&lt;h2 id="Bugfixes"&gt;Bugfixes&lt;/h2&gt;
&lt;ul&gt;&lt;li&gt;(bug T74222) The original patch for T74222 was reverted as unnecessary.
&lt;/li&gt;&lt;li&gt;Fixed a couple of entries in RELEASE-NOTES-1.24.
&lt;/li&gt;&lt;li&gt;(bug T76168) OutputPage: Add accessors for some protected properties.
&lt;/li&gt;&lt;li&gt;(bug T74834) Make 1.24 branch directly installable under PostgreSQL.
&lt;/li&gt;&lt;li&gt;Add missing $ in front of variable in OutputPage.php
&lt;/li&gt;&lt;/ul&gt;&lt;h2 id="Securityfixesinextensions"&gt;Security fixes in extensions&lt;/h2&gt;
&lt;ul&gt;&lt;li&gt;(bug T77624) [SECURITY] Extension:Listings: missing validation in the
'name' and 'url' parameters.
&lt;/li&gt;&lt;li&gt;(bug T73111) [SECURITY] Extension:ExpandTemplates: parses user input
as wikitext and shows a preview, yet it fails to add an edit token to
the form and check it. This can be exploited as an XSS when
$wgRawHtml = true. Note this only affects the 1.19/1.22 branches.
&lt;/li&gt;&lt;li&gt;(bug T76195) [SECURITY] Extension:TemplateSandbox:
Special:TemplateSandbox needs edit token when raw HTML is allowed
&lt;/li&gt;&lt;li&gt;(bug T69180) [SECURITY] Extension:Hovercards: XSS in text extracts.
&lt;/li&gt;&lt;li&gt;(bug T73167) [SECURITY] Extension:Scribunto allows cross-origin
leakage of data from a wiki through timing
&lt;/li&gt;&lt;li&gt;(bug T71209) [SECURITY] Extension:TimedMediaHandler: Patch getid3
library for CVE-2014-2053.
&lt;/li&gt;&lt;/ul&gt;&lt;p&gt;
Full release notes for 1.23.8:
&lt;a class="ext-link" href="https://www.mediawiki.org/wiki/Release_notes/1.23"&gt;&lt;span class="icon"&gt;​&lt;/span&gt;https://www.mediawiki.org/wiki/Release_notes/1.23&lt;/a&gt;
&lt;/p&gt;
&lt;/blockquote&gt;
</description>
    <language>en-us</language>
    <image>
      <title>Transition Technology</title>
      <url>/trac/chrome/site/TransitionNetwork-Logo-Web-Small.jpg</url>
      <link>http://localhost:8080/trac/ticket/816</link>
    </image>
    <generator>Trac 0.12.5</generator>
    <item>
      
        <dc:creator>chris</dc:creator>

      <pubDate>Thu, 18 Dec 2014 11:29:25 GMT</pubDate>
      <title>hours, status, totalhours changed; resolution set</title>
      <link>http://localhost:8080/trac/ticket/816#comment:1</link>
      <guid isPermaLink="false">http://localhost:8080/trac/ticket/816#comment:1</guid>
      <description>
          &lt;ul&gt;
            &lt;li&gt;&lt;strong&gt;hours&lt;/strong&gt;
                changed from &lt;em&gt;0.0&lt;/em&gt; to &lt;em&gt;0.25&lt;/em&gt;
            &lt;/li&gt;
            &lt;li&gt;&lt;strong&gt;status&lt;/strong&gt;
                changed from &lt;em&gt;new&lt;/em&gt; to &lt;em&gt;closed&lt;/em&gt;
            &lt;/li&gt;
            &lt;li&gt;&lt;strong&gt;resolution&lt;/strong&gt;
                set to &lt;em&gt;fixed&lt;/em&gt;
            &lt;/li&gt;
            &lt;li&gt;&lt;strong&gt;totalhours&lt;/strong&gt;
                changed from &lt;em&gt;0.0&lt;/em&gt; to &lt;em&gt;0.25&lt;/em&gt;
            &lt;/li&gt;
          &lt;/ul&gt;
        &lt;p&gt;
Following the &lt;a class="wiki" href="http://localhost:8080/trac/wiki/MediaWiki#Updates"&gt;wiki:MediaWiki#Updates&lt;/a&gt; notes:
&lt;/p&gt;
&lt;pre class="wiki"&gt;sudo -i
cd /web/wiki.transitionnetwork.org
export MW="1.23.8"
wget http://releases.wikimedia.org/mediawiki/1.23/mediawiki-$MW.tar.gz -O mediawiki-$MW.tar.gz
wget http://releases.wikimedia.org/mediawiki/1.23/mediawiki-$MW.tar.gz.sig -O mediawiki-$MW.tar.gz.sig
gpg --verify mediawiki-$MW.tar.gz.sig
tar -zxvf mediawiki-$MW.tar.gz
rsync -av mediawiki-$MW/ www/
chown root:root -R www/
chown -R www-data:www-data www/cache/
chown -R www-data:www-data www/images/
cd www/maintenance/
php update.php
cd /web/wiki.transitionnetwork.org
rm mediawiki-$MW.tar.gz mediawiki-$MW.tar.gz.sig
rm -rf mediawiki-$MW
&lt;/pre&gt;&lt;p&gt;
The site was tested and all seems to be working fine so closing this ticket.
&lt;/p&gt;
      </description>
      <category>Ticket</category>
    </item>
 </channel>
</rss>