~ubuntu-branches/ubuntu/intrepid/mediawiki/intrepid-updates

  • Committer: Bazaar Package Importer
  • Author(s): Andreas Wenning
  • Date: 2009-02-01 08:53:13 UTC
  • Revision ID: james.westby@ubuntu.com-20090201085313-7p0thizuv91oahlr
Tags: 1:1.12.0-2ubuntu0.2
* SECURITY UPDATE:
  - CVE-2008-5249
  - CVE-2008-5250
  - CVE-2008-5252
  - other security-related problems (see full patch description).
  - patch taken directly from Debian
  - http://bugs.debian.org/cgi-bin/bugreport.cgi?bug=508870
  - http://bugs.debian.org/cgi-bin/bugreport.cgi?bug=508869
  - http://lists.wikimedia.org/pipermail/mediawiki-announce/2008-December/000080.html
* debian/patches/CVE-2008-5249_CVE-2008-5250_CVE-2008-5252.patch:
  - Fixed output escaping for reporting of non-MediaWiki exceptions. 
    Potential XSS if an extension throws one of these with user input.
  - Avoid fatal error in profileinfo.php when not configured.
  - Fixed CSRF vulnerability in Special:Import. Fixed input validation in 
    transwiki import feature.
  - Add a .htaccess to deleted images directory for additional protection
    against exposure of deleted files with known SHA-1 hashes on default
    installations.
  - Fixed XSS vulnerability for Internet Explorer clients, via file uploads
    which are interpreted by IE as HTML.
  - Fixed XSS vulnerability for clients with SVG scripting, on wikis where SVG
    uploads are enabled. Firefox 1.5+ is affected.
  - Avoid streaming uploaded files to the user via index.php. This allows 
    security-conscious users to serve uploaded files via a different domain,
    and thus client-side scripts executed from that domain cannot access the
    login cookies. Affects Special:Undelete, img_auth.php and thumb.php.
  - When streaming files via index.php, use the MIME type detected from the
    file extension, not from the data. This reduces the XSS attack surface.
  - Blacklist redirects via Special:Filepath. Such redirects exacerbate any 
    XSS vulnerabilities involving uploads of files containing scripts.
Filename Latest Rev Last Changed Committer Comment Size
..
bin 1.1.5 16 years ago Bazaar Package Importer Import upstream version 1.11.0 Diff
config 1 18 years ago Bazaar Package Importer Import upstream version 1.4.10 Diff
debian 8 17 years ago Bazaar Package Importer Initial Release Diff
docs 1 18 years ago Bazaar Package Importer Import upstream version 1.4.10 Diff
extensions 1 18 years ago Bazaar Package Importer Import upstream version 1.4.10 Diff
images 1 18 years ago Bazaar Package Importer Import upstream version 1.4.10 Diff
includes 1 18 years ago Bazaar Package Importer Import upstream version 1.4.10 Diff
languages 1 18 years ago Bazaar Package Importer Import upstream version 1.4.10 Diff
locale 1.1.5 16 years ago Bazaar Package Importer Import upstream version 1.11.0 Diff
maintenance 1 18 years ago Bazaar Package Importer Import upstream version 1.4.10 Diff
math 1 18 years ago Bazaar Package Importer Import upstream version 1.4.10 Diff
serialized 1.1.5 16 years ago Bazaar Package Importer Import upstream version 1.11.0 Diff
skins 1 18 years ago Bazaar Package Importer Import upstream version 1.4.10 Diff
t 1.1.5 16 years ago Bazaar Package Importer Import upstream version 1.11.0 Diff
tests 1 18 years ago Bazaar Package Importer Import upstream version 1.4.10 Diff
AdminSettings.sample 1.1.5 16 years ago Bazaar Package Importer Import upstream version 1.11.0 825 bytes Diff Download File
api.php 1.1.6 16 years ago Bazaar Package Importer Import upstream version 1.11.1 2.8 KB Diff Download File
api.php5 1.1.8 16 years ago Bazaar Package Importer Import upstream version 1.12.0 25 bytes Diff Download File
COPYING 1.1.5 16 years ago Bazaar Package Importer Import upstream version 1.11.0 17.5 KB Diff Download File
FAQ 1.1.6 16 years ago Bazaar Package Importer Import upstream version 1.11.1 164 bytes Diff Download File
HISTORY 1.1.8 16 years ago Bazaar Package Importer Import upstream version 1.12.0 261 KB Diff Download File
img_auth.php 1.1.8 16 years ago Bazaar Package Importer Import upstream version 1.12.0 2.4 KB Diff Download File
img_auth.php5 1.1.8 16 years ago Bazaar Package Importer Import upstream version 1.12.0 31 bytes Diff Download File
index.php 1.1.8 16 years ago Bazaar Package Importer Import upstream version 1.12.0 3.1 KB Diff Download File
index.php5 1.1.8 16 years ago Bazaar Package Importer Import upstream version 1.12.0 28 bytes Diff Download File
INSTALL 1.1.6 16 years ago Bazaar Package Importer Import upstream version 1.11.1 3.8 KB Diff Download File
install-utils.inc 1.1.8 16 years ago Bazaar Package Importer Import upstream version 1.12.0 3.6 KB Diff Download File
Makefile 1.1.5 16 years ago Bazaar Package Importer Import upstream version 1.11.0 569 bytes Diff Download File
opensearch_desc.php 1.1.8 16 years ago Bazaar Package Importer Import upstream version 1.12.0 1.4 KB Diff Download File
opensearch_desc.php5 1.1.8 16 years ago Bazaar Package Importer Import upstream version 1.12.0 39 bytes Diff Download File
profileinfo.php 1.1.8 16 years ago Bazaar Package Importer Import upstream version 1.12.0 6.4 KB Diff Download File
README 1.1.8 16 years ago Bazaar Package Importer Import upstream version 1.12.0 3.4 KB Diff Download File
redirect.php 1.1.5 16 years ago Bazaar Package Importer Import upstream version 1.11.0 289 bytes Diff Download File
redirect.php5 1.1.8 16 years ago Bazaar Package Importer Import upstream version 1.12.0 31 bytes Diff Download File
redirect.phtml 1.1.5 16 years ago Bazaar Package Importer Import upstream version 1.11.0 91 bytes Diff Download File
RELEASE-NOTES 1.1.8 16 years ago Bazaar Package Importer Import upstream version 1.12.0 38.3 KB Diff Download File
StartProfiler.php 1.1.5 16 years ago Bazaar Package Importer Import upstream version 1.11.0 603 bytes Diff Download File
Test.php 1.1.5 16 years ago Bazaar Package Importer Import upstream version 1.11.0 12.5 KB Diff Download File
thumb.php 1.1.8 16 years ago Bazaar Package Importer Import upstream version 1.12.0 3.4 KB Diff Download File
thumb.php5 1.1.8 16 years ago Bazaar Package Importer Import upstream version 1.12.0 29 bytes Diff Download File
trackback.php 1.1.8 16 years ago Bazaar Package Importer Import upstream version 1.12.0 1.3 KB Diff Download File
UPGRADE 1.1.8 16 years ago Bazaar Package Importer Import upstream version 1.12.0 12.8 KB Diff Download File
wiki.phtml 1.1.5 16 years ago Bazaar Package Importer Import upstream version 1.11.0 88 bytes Diff Download File