[ubuntu/hardy-security] mediawiki_1.11.2-2ubuntu0.6_i386_translations.tar.gz, mediawiki_1.11.2-2ubuntu0.6_hppa_translations.tar.gz, mediawiki_1.11.2-2ubuntu0.6_ia64_translations.tar.gz, mediawiki_1.11.2-2ubuntu0.6_powerpc_translations.tar.gz, mediawiki_1.11.2-2ubuntu0.6_amd64_translations.tar.gz, mediawiki_1.11.2-2ubuntu0.6_sparc_translations.tar.gz (delayed), mediawiki, mediawiki_1.11.2-2ubuntu0.6_lpia_translations.tar.gz 1:1.11.2-2ubuntu0.6 (Accepted)
Ubuntu Installer
archive at ubuntu.com
Wed Jun 2 20:03:43 BST 2010
mediawiki (1:1.11.2-2ubuntu0.6) hardy-security; urgency=low
* SECURITY UPDATE: A CSRF vulnerability was discovered in our login
interface. Although regular logins are protected as of 1.15.3, it was
discovered that the account creation and password reset features were not
protected from CSRF. This could lead to unauthorised access to private
wikis. (LP: #586773)
- debian/patches/CSRF-Special-Userlogin-no-CVE_rev-66991.patch
- patch from upstream SVN rev. 66991
- http://lists.wikimedia.org/pipermail/mediawiki-announce/2010-May/000091.html
- https://bugzilla.wikimedia.org/show_bug.cgi?id=23371
* SECURITY UPDATE: Noncompliant CSS parsing behaviour in Internet Explorer
allows attackers to construct CSS strings which are treated as safe by
previous versions of MediaWiki, but are decoded to unsafe strings by
Internet Explorer. (LP: #586773)
- debian/patches/XSS-IE-no-CVE_rev-66992.patch
- patch from upstream SVN rev. 66992
- http://lists.wikimedia.org/pipermail/mediawiki-announce/2010-May/000091.html
- https://bugzilla.wikimedia.org/show_bug.cgi?id=23687
Date: Mon, 31 May 2010 00:45:24 +0200
Changed-By: Andreas Wenning <awen at awen.dk>
Maintainer: Ubuntu MOTU Developers <ubuntu-motu at lists.ubuntu.com>
https://launchpad.net/ubuntu/hardy/+source/mediawiki/1:1.11.2-2ubuntu0.6
-------------- next part --------------
Format: 1.7
Date: Mon, 31 May 2010 00:45:24 +0200
Source: mediawiki
Binary: mediawiki mediawiki-math
Architecture: source
Version: 1:1.11.2-2ubuntu0.6
Distribution: hardy-security
Urgency: low
Maintainer: Ubuntu MOTU Developers <ubuntu-motu at lists.ubuntu.com>
Changed-By: Andreas Wenning <awen at awen.dk>
Description:
mediawiki - website engine for collaborative work
mediawiki-math - math rendering plugin for MediaWiki
Launchpad-Bugs-Fixed: 586773 586773
Changes:
mediawiki (1:1.11.2-2ubuntu0.6) hardy-security; urgency=low
.
* SECURITY UPDATE: A CSRF vulnerability was discovered in our login
interface. Although regular logins are protected as of 1.15.3, it was
discovered that the account creation and password reset features were not
protected from CSRF. This could lead to unauthorised access to private
wikis. (LP: #586773)
- debian/patches/CSRF-Special-Userlogin-no-CVE_rev-66991.patch
- patch from upstream SVN rev. 66991
- http://lists.wikimedia.org/pipermail/mediawiki-announce/2010-May/000091.html
- https://bugzilla.wikimedia.org/show_bug.cgi?id=23371
* SECURITY UPDATE: Noncompliant CSS parsing behaviour in Internet Explorer
allows attackers to construct CSS strings which are treated as safe by
previous versions of MediaWiki, but are decoded to unsafe strings by
Internet Explorer. (LP: #586773)
- debian/patches/XSS-IE-no-CVE_rev-66992.patch
- patch from upstream SVN rev. 66992
- http://lists.wikimedia.org/pipermail/mediawiki-announce/2010-May/000091.html
- https://bugzilla.wikimedia.org/show_bug.cgi?id=23687
Files:
7715549b178e7b04a41b2e91f3885952 972 web optional mediawiki_1.11.2-2ubuntu0.6.dsc
dd091ceb082016cd87cfd1b859d8ed82 66110 web optional mediawiki_1.11.2-2ubuntu0.6.diff.gz
Original-Maintainer: Mediawiki Maintenance Team <pkg-mediawiki-devel at lists.alioth.debian.org>
More information about the Hardy-changes
mailing list