Brion Vibber | 6 Oct 2005 06:48
Picon
Favicon
Gravatar

MediaWiki 1.4.11, 1.3.17 security updates


MediaWiki 1.4.11 and 1.3.17 are a security maintenance releases. Unsafe
handling of CSS by Microsoft Internet Explorer could be exploited to
produce cross-site scripting attacks by JavaScript injection to clients
running that browser.

This release blacklists several additional variants from use in HTML
inline style attributes.

All publicly accessible wikis are recommended to upgrade to reduce the
risk to visitors using Microsoft web browsers.

Note: the MediaWiki 1.4.x and 1.3.x series are not compatible with PHP
5.0.5 or higher. Upgrade to the 1.5.0 release if you require this
version of PHP 5.

Release notes:
http://sourceforge.net/project/shownotes.php?release_id=361505 1.4.11
http://sourceforge.net/project/shownotes.php?release_id=361504 1.3.17

Download:
http://prdownloads.sourceforge.net/wikipedia/mediawiki-1.4.11.tar.gz?download
http://prdownloads.sourceforge.net/wikipedia/mediawiki-1.3.17.tar.gz?download

MD5 checksums:
023e296dea4274af190f286064e1be27  mediawiki-1.4.11.tar.gz
d2fe05847162501f2aa7b8cb65114f69  mediawiki-1.3.17.tar.gz

Before asking for help, try the FAQ:
http://meta.wikimedia.org/wiki/MediaWiki_FAQ
(Continue reading)

Brion Vibber | 6 Oct 2005 06:48
Picon
Favicon
Gravatar

MediaWiki 1.5.0 released


MediaWiki 1.5.0 is the new stable release branch of MediaWiki, and is
recommended for all new installations.

See the release notes (link below) for details of new features and
requirements.

Any wikis running a 1.5 beta or release candidate are strongly
recommended to upgrade to the final release, which includes a number of
bug fixes and a security fix for CSS bugs in Microsoft Internet Explorer.

IMPORTANT: Running a 1.3 or 1.4 wiki and don't want to jump to 1.5 yet?
Be sure to upgrade to 1.3.17 or 1.4.11, also released today. Versions
prior to 1.3.16 and 1.4.10 have a serious data corruption bug which is
triggered by a spambot known to operate in the wild.

Release notes:
http://sourceforge.net/project/shownotes.php?release_id=361506

Download:
http://prdownloads.sourceforge.net/wikipedia/mediawiki-1.5.0.tar.gz?download

MD5 checksum:
b431e82ee5fd0d619d17cb2d417387c3  mediawiki-1.5.0.tar.gz

Before asking for help, try the FAQ:
http://meta.wikimedia.org/wiki/MediaWiki_FAQ

Low-traffic release announcements mailing list:
http://mail.wikipedia.org/mailman/listinfo/mediawiki-announce
(Continue reading)

Brion Vibber | 26 Oct 2005 12:55
Picon
Favicon
Gravatar

MediaWiki 1.5.1 released


MediaWiki 1.5.1 is a bugfix and security maintenance release, and is a
recommended upgrade for all installations.

This release includes further corrections to the inline CSS style
sanitation which works around a JavaScript "feature" on Microsoft
Internet Explorer. Users of Microsoft Internet Explorer for Windows may
be vulnerable to XSS injections on prior versions; users of
standards-compliant browsers are not vulnerable.

Major fixes include:
* Image pages work again with resizing disabled
* Works in MySQL 5.0 strict mode

There is experimental support in this release for explicitly declaring
the UTF-8 charset in the database; this has been tested with MySQL
5.0.15 but should work on 4.1 as well.

IMPORTANT: Changing this setting on an existing wiki may produce
interesting data corruption, depending on server configuration. Page
contents should, usually, be unaffected, but page titles and other items
may be. Limitations in MySQL's Unicode support mean that characters
outside the BMP cannot be used in page titles or various other fields
when using this mode.

Table definitions are in maintenance/mysql5/tables.sql, and the runtime
option to send 'SET NAMES utf8' is set by $wgDBmysql5 = true.

(MySQL 3.23.x and 4.0.x do not support character set declarations; on
these versions MediaWiki simply works with UTF-8 data and MySQL is
(Continue reading)

Brion Vibber | 6 Oct 2005 06:48
Picon
Favicon
Gravatar

MediaWiki 1.4.11, 1.3.17 security updates


MediaWiki 1.4.11 and 1.3.17 are a security maintenance releases. Unsafe
handling of CSS by Microsoft Internet Explorer could be exploited to
produce cross-site scripting attacks by JavaScript injection to clients
running that browser.

This release blacklists several additional variants from use in HTML
inline style attributes.

All publicly accessible wikis are recommended to upgrade to reduce the
risk to visitors using Microsoft web browsers.

Note: the MediaWiki 1.4.x and 1.3.x series are not compatible with PHP
5.0.5 or higher. Upgrade to the 1.5.0 release if you require this
version of PHP 5.

Release notes:
http://sourceforge.net/project/shownotes.php?release_id=361505 1.4.11
http://sourceforge.net/project/shownotes.php?release_id=361504 1.3.17

Download:
http://prdownloads.sourceforge.net/wikipedia/mediawiki-1.4.11.tar.gz?download
http://prdownloads.sourceforge.net/wikipedia/mediawiki-1.3.17.tar.gz?download

MD5 checksums:
023e296dea4274af190f286064e1be27  mediawiki-1.4.11.tar.gz
d2fe05847162501f2aa7b8cb65114f69  mediawiki-1.3.17.tar.gz

Before asking for help, try the FAQ:
http://meta.wikimedia.org/wiki/MediaWiki_FAQ
(Continue reading)

Brion Vibber | 6 Oct 2005 06:48
Picon
Favicon
Gravatar

MediaWiki 1.5.0 released


MediaWiki 1.5.0 is the new stable release branch of MediaWiki, and is
recommended for all new installations.

See the release notes (link below) for details of new features and
requirements.

Any wikis running a 1.5 beta or release candidate are strongly
recommended to upgrade to the final release, which includes a number of
bug fixes and a security fix for CSS bugs in Microsoft Internet Explorer.

IMPORTANT: Running a 1.3 or 1.4 wiki and don't want to jump to 1.5 yet?
Be sure to upgrade to 1.3.17 or 1.4.11, also released today. Versions
prior to 1.3.16 and 1.4.10 have a serious data corruption bug which is
triggered by a spambot known to operate in the wild.

Release notes:
http://sourceforge.net/project/shownotes.php?release_id=361506

Download:
http://prdownloads.sourceforge.net/wikipedia/mediawiki-1.5.0.tar.gz?download

MD5 checksum:
b431e82ee5fd0d619d17cb2d417387c3  mediawiki-1.5.0.tar.gz

Before asking for help, try the FAQ:
http://meta.wikimedia.org/wiki/MediaWiki_FAQ

Low-traffic release announcements mailing list:
http://mail.wikipedia.org/mailman/listinfo/mediawiki-announce
(Continue reading)


Gmane