Chris Steipp | 30 Apr 2013 22:14
Picon

MediaWiki Security Release: 1.20.5 and 1.19.6

I would like to announce the release of MediaWiki 1.20.5 and 1.19.6.
These releases fix 2 security related issues that could affect users
of MediaWiki. Download links are given at the end of this email.

* Jan Schejbal / Hatforce.com reported that SVG script filtering could
be bypassed for Chrome and Firefox clients by using an encoding that
MediaWiki understood, but these browsers interpreted as UTF-8.
<https://bugzilla.wikimedia.org/show_bug.cgi?id=47304>

* Internal review discovered that extensions were not given the
opportunity to disable a password reset, which could lead to
circumvention of two-factor authentication.
<https://bugzilla.wikimedia.org/show_bug.cgi?id=46590>

Full release notes for 1.20.5:
<https://www.mediawiki.org/wiki/Release_notes/1.20>

Full release notes for 1.19.6:
<https://www.mediawiki.org/wiki/Release_notes/1.19>

For information about how to upgrade, see
<https://www.mediawiki.org/wiki/Manual:Upgrading>

**********************************************************************
   1.20.5
**********************************************************************
Download:
http://download.wikimedia.org/mediawiki/1.20/mediawiki-1.20.5.tar.gz

Patch to previous version (1.20.4), without interface text:
(Continue reading)

Chris Steipp | 29 Apr 2013 22:14
Picon

Pre-Release Announcement for MediaWiki 1.19.6 and 1.20.5

This is a notice that on Tuesday, April 30th between 20:00-21:00 UTC
(1-2pm PDT) Wikimedia Foundation will release security updates for
current and supported branches of the MediaWiki software. Downloads
and patches will be available at that time, with the git repositories
updated later that afternoon.

_______________________________________________
MediaWiki announcements mailing list
To unsubscribe, go to:
https://lists.wikimedia.org/mailman/listinfo/mediawiki-announce
Chris Steipp | 15 Apr 2013 22:37
Picon

MediaWiki Security Release: 1.20.4 and 1.19.5

I would like to announce the release of MediaWiki 1.20.4 and 1.19.5.
These releases fix 3 security related bugs that could affect users of
MediaWiki. Download links are given at the end of this email.

* An internal review discovered that specially crafted Lua function
names could lead to XSS.
<https://bugzilla.wikimedia.org/show_bug.cgi?id=46084>

* Daniel Franke reported that during SVG parsing, MediaWiki failed to
prevent XML external entity (XXE) processing. This could lead to local
file disclosure, or potentially remote command execution in
environments that have enabled expect:// handling.
<https://bugzilla.wikimedia.org/show_bug.cgi?id=46859>

* Internal review also discovered that Special:Import, and
Extension:RSS failed to prevent XML external entity (XXE) processing.
<https://bugzilla.wikimedia.org/show_bug.cgi?id=47251>

Full release notes for 1.20.4:
<https://www.mediawiki.org/wiki/Release_notes/1.20>

Full release notes for 1.19.5:
<https://www.mediawiki.org/wiki/Release_notes/1.19>

For information about how to upgrade, see
<https://www.mediawiki.org/wiki/Manual:Upgrading>

**********************************************************************
   1.20.4
**********************************************************************
(Continue reading)

Chris Steipp | 13 Apr 2013 00:09
Picon

Pre-Release Announcement for MediaWiki 1.19.5 and 1.20.4

This is a notice that on Monday, April 15th between 20:00-21:00 UTC
(1-2pm PDT) Wikimedia Foundation will release security updates for
current and supported branches of the MediaWiki software. Downloads
and patches will be available at that time, with the git repositories
updated later that afternoon. CVSS scores are between 4.3 and 7.1,
most users will want to update.

_______________________________________________
MediaWiki announcements mailing list
To unsubscribe, go to:
https://lists.wikimedia.org/mailman/listinfo/mediawiki-announce
Chris Steipp | 4 Mar 2013 20:19
Picon

MediaWiki security release: 1.20.3 and 1.19.4

I would like to announce the release of MediaWiki 1.20.3 and 1.19.4.
These releases fix 3 security related bugs that could affect users of
MediaWiki. Download links are given at the end of this email.

* By default, the curl library passed 'true' to CURLOPT_SSL_VERIFYHOST
when establishing an SSL connection, instead of '2'.
<https://bugzilla.wikimedia.org/show_bug.cgi?id=44135>
<https://bugzilla.wikimedia.org/show_bug.cgi?id=42441>

* MediaWiki developer Krenair discovered that the full user object,
including password hash, could be returned when unblocking a user by
the API. Exploitation of this vulnerability requires the user to have
permissions to unblock users, by default this is limited to users in
the sysop group.
<https://bugzilla.wikimedia.org/show_bug.cgi?id=43518>

* MediaWiki developer Platonides discovered that the maintenance
script mwdoc-filter.php did not check if it was being run via the CLI,
and could allow an attacker to read arbitrary files if PHP's
register_globals was enabled and the .htaccess file in the maintenance
directory, which by default denies access for all users, was disabled.
<https://bugzilla.wikimedia.org/show_bug.cgi?id=45355>

Full release notes for 1.20.3:
<https://www.mediawiki.org/wiki/Release_notes/1.20>

Full release notes for 1.19.4:
<https://www.mediawiki.org/wiki/Release_notes/1.19>

For information about how to upgrade, see
(Continue reading)

Chris Steipp | 1 Mar 2013 20:08
Picon

Pre-Release Announcement for MediaWiki 1.19.4 and 1.20.3

This is a notice to let you know that on Monday, March 4th between
21:00-22:00 UTC (1-2pm PST) Wikimedia Foundation will release security
updates for current and supported branches of the MediaWiki software.
Downloads and patches will be available at that time, with the git
repositories updated later that afternoon.

_______________________________________________
MediaWiki announcements mailing list
To unsubscribe, go to:
https://lists.wikimedia.org/mailman/listinfo/mediawiki-announce
Chris Steipp | 5 Dec 2012 00:20
Picon

MediaWiki maintenance release 1.20.2

I would like to announce the release of MediaWiki 1.20.2. This is a maintenance
release correcting issues from the 1.20.1 security release.

* (bug 42638) Fixes action=options&reset=1 in the API, and fixes unit tests.
* (bug 42370) Fixes backport of 60cc060 to use mDoneWrites instead of
   mTrxDoneWrites.

Full release notes:
<https://www.mediawiki.org/wiki/Release_notes/1.20>

**********************************************************************
Download:
<http://download.wikimedia.org/mediawiki/1.20/mediawiki-1.20.2.tar.gz>

Patch to previous version (1.20.1):
<http://download.wikimedia.org/mediawiki/1.20/mediawiki-1.20.2.patch.gz>

GPG signatures:
<http://download.wikimedia.org/mediawiki/1.20/mediawiki-1.20.2.tar.gz.sig>
<http://download.wikimedia.org/mediawiki/1.20/mediawiki-1.20.2.patch.gz.sig>

Public keys:
<https://secure.wikimedia.org/keys.html>

_______________________________________________
MediaWiki announcements mailing list
To unsubscribe, go to:
https://lists.wikimedia.org/mailman/listinfo/mediawiki-announce

(Continue reading)

Chris Steipp | 30 Nov 2012 02:30
Picon

MediaWiki security release: 1.20.1, 1.19.3 and 1.18.6

I would like to announce the release of MediaWiki 1.20.1, 1.19.3 and
1.18.6. These releases fix 3 security related bugs that could affect
users of MediaWiki. Download links are given at the end of this email
. Please note that support for the MediaWiki 1.18  branch ends this
month.

* During an internal review, it was discovered that MediaWiki core is
vulnerable to session fixation attacks. Successful exploitation could
allow an attacker to compromise another user's account. This issues
has been assigned CVE-2012-5391.  A similar vulnerability was also
identified in the CentralAuth Extension, and assigned CVE-2012-5395.
<https://bugzilla.wikimedia.org/show_bug.cgi?id=40995>
<https://bugzilla.wikimedia.org/show_bug.cgi?id=40962>

* Wikipedia user PleaseStand discovered that a new API feature in
MediaWiki 1.20 allowed for HTML code to be injected into the
"editfont" option. Since this option only affects the current user,
exploitation for XSS is difficult. However, users of MediaWiki 1.20
are encouraged to upgrade.
<https://bugzilla.wikimedia.org/show_bug.cgi?id=42202>

* Wikipedia user PleaseStand discovered that a PCRE backtrack limit
could easily be exceeded, causing recent changes and history pages to
fail to display. Since these pages are often used for fighting spam
and vandalism, public wikis are encouraged to update.
<https://bugzilla.wikimedia.org/show_bug.cgi?id=41400>

Full release notes for 1.20.1:
<https://www.mediawiki.org/wiki/Release_notes/1.20>

(Continue reading)

Chris Steipp | 28 Nov 2012 05:29
Picon

Pre-Release Announcement for MediaWiki 1.18.6, 1.19.3, and 1.20.1

On Thursday, November 29th, between 21:00-22:00 UTC (1-2pm PST)
Wikimedia Foundation will release security updates for current and
supported branches of the MediaWiki software. We are providing this
pre-announcement as a courtesy for administrators to be ready to
accept the fix for these on Thursday. We will send another
announcement email when the patches and tar files are ready for
download.

* Vulnerabilities were found in both MediaWiki core and the
CentralAuth extension. Successful exploitation could allow an attacker
to compromise another user's account. Risk is considered moderate
(CVSS Base Score: 4).
* One vulnerability was discovered that could allow an attacker to
prevent users from viewing Special:RecentChanges, and other pages,
which could prevent the detection of SPAM or vandalism. Public wikis
are encouraged to upgrade.
* A flaw in the MediaWiki 1.20 API could allow a stored XSS.
Exploitation requires user interaction or an existing XSS
vulnerability, so risk of exploitation is low.

For information about how to upgrade, see
<https://www.mediawiki.org/wiki/Manual:Upgrading>

_______________________________________________
MediaWiki announcements mailing list
To unsubscribe, go to:
https://lists.wikimedia.org/mailman/listinfo/mediawiki-announce

Mark A. Hershberger | 7 Nov 2012 02:22
Gravatar

MediaWiki 1.20.0 released


I'm happy to announce the availability of the first stable release
of the new MediaWiki 1.20 release series.

MediaWiki 1.20 is a large release that contains many new features and
bug fixes. This is a summary of the major changes of interest to users.
You can consult the RELEASE-NOTES-1.20 file for the full list of changes
in this version.

Our thanks go to everyone who helped to improve MediaWiki by testing
the beta release and submitting bug reports.

== What's new? ==

MediaWiki 1.20 brings the usual host of various bugfixes and new features.

* Minimum PHP version is now 5.3.2.

* New diff view, greatly improved in clarity especially for
whitespace and other small changes and color-blind users.

* New special page Special:MostInterwikis.

* New magic word {{PAGEID}} which gives the current page ID.

* The info action has been reimplemented.

Internationalization:

* New languages supported: Emilian (egl), Tornedalen Finnish (fit),
(Continue reading)

Chris Steipp | 31 Aug 2012 06:26
Picon

MediaWiki security release: 1.19.2 and 1.18.5

I would like to announce the release of MediaWiki 1.19.2 and 1.18.5.
These releases fix 6 security related bugs that could affect users of
MediaWiki. Download links are given at the end of this email.

* Wikipedia administrator Writ Keeper discovered a stored XSS (HTML
injection) vulnerability. This was possible due to the handling of
link text on File: links for nonexistent files. MediaWiki 1.16 and
later is affected. For more details, see
<https://bugzilla.wikimedia.org/show_bug.cgi?id=39700>

* User Fomafix reported several DOM-based XSS vulnerabilities, made
possible by a combination of loose filtering of the uselang parameter,
and JavaScript gadgets on various language Wikipedias. For more
details, see <https://bugzilla.wikimedia.org/show_bug.cgi?id=37587>

* During internal review, it was discovered that CSRF tokens,
available via the api, were not protected with X-Frame-Options
headers. This could lead to a CSRF vulnerability if the API response
is embedded in an external website using an iframe. For more details,
see <https://bugzilla.wikimedia.org/show_bug.cgi?id=39180>

* During internal review, it was discovered extensions were not always
allowed to prevent the account creation action. This allowed users
blocked by the GlobalBlocking extension to create accounts. For more
details, see <https://bugzilla.wikimedia.org/show_bug.cgi?id=39824>

* During internal review, it was discovered that password data was
always saved to the local MediaWiki database, even if authentication
was handled by an extension, such as LDAP. This could allow a
compromised MediaWiki installation to leak information about user's
(Continue reading)


Gmane