--------------------------------------------------------------------------------
Fedora Update Notification
FEDORA-2009-7750
2009-07-19 03:26:16
--------------------------------------------------------------------------------

Name        : mediawiki
Product     : Fedora 10
Version     : 1.15.1
Release     : 48.fc10
URL         : https://www.mediawiki.org/wiki/MediaWiki
Summary     : A wiki engine
Description :
MediaWiki is the software used for Wikipedia and the other Wikimedia
Foundation websites. Compared to other wikis, it has an excellent
range of features and support for high-traffic websites using multiple
servers
This package supports wiki farms. Copy /var/www/wiki over to the
desired wiki location and configure it through the web
interface. Remember to remove the config dir after completing the
configuration.

--------------------------------------------------------------------------------
Update Information:

This update upgrades mediawiki code to 1.15.1 and fixes some path references.
Upstream comments:  This is a security and bugfix release of MediaWiki 1.15.1
and 1.14.1.    A cross-site scripting (XSS) vulnerability was discovered. Only
versions 1.14.0, 1.15.0 and release candidates for those releases are affected.
--------------------------------------------------------------------------------
ChangeLog:

* Mon Jul 13 2009 Axel Thimm  - 1.15.1-48
- Update to 1.15.1 (Fixes XSS vulnerability).
* Sat Jul 11 2009 Axel Thimm  - 1.15.0-47
- Fix api.php breakage.
* Sat Jun 13 2009 Axel Thimm  - 1.15.0-46
- Update to 1.15.0.
* Thu Apr 16 2009 S390x secondary arch maintainer 
- ExcludeArch sparc64, s390, s390x as we don't have OCaml on those archs
  (added sparc64 per request from the sparc maintainer)
* Sat Feb 28 2009 Axel Thimm  - 1.14.0-45
- Update to 1.14.0.
* Sun Feb 22 2009 Axel Thimm  - 1.13.4-44
- Split package up, so some users can decide to not install math
  support (results in smaller installs), see RH bug #485447.
* Wed Feb 18 2009 Axel Thimm  - 1.13.4-43
- Update to 1.13.4, closes RH bug #485728.
* Tue Dec 23 2008 Axel Thimm  - 1.13.3-42
- Update to 1.13.3, closes RH bug #476621 (CVE-2008-5249,
  CVE-2008-5250, CVE-2008-5252 and CVE-2008-5687, CVE-2008-5688)
--------------------------------------------------------------------------------
References:

  [ 1 ] Bug #484855 - mediawiki api.php has bad path
        https://bugzilla.redhat.com/show_bug.cgi?id=484855
  [ 2 ] Bug #494362 - maintenance scripts fail
        https://bugzilla.redhat.com/show_bug.cgi?id=494362
  [ 3 ] Bug #494880 - Uploading fails
        https://bugzilla.redhat.com/show_bug.cgi?id=494880
--------------------------------------------------------------------------------

This update can be installed with the "yum" update program.  Use 
su -c 'yum update mediawiki' at the command line.
For more information, refer to "Managing Software with yum",
available at .

All packages are signed with the Fedora Project GPG key.  More details on the
GPG keys used by the Fedora Project can be found at
https://fedoraproject.org/security/
--------------------------------------------------------------------------------

_______________________________________________
Fedora-package-announce mailing list
Fedora-package-announce@redhat.com
http://www.redhat.com/mailman/listinfo/fedora-package-announce

Fedora 10 Update: mediawiki-1.15.1-48.fc10

July 19, 2009
This update upgrades mediawiki code to 1.15.1 and fixes some path references. Upstream comments: This is a security and bugfix release of MediaWiki 1.15.1 and 1.14.1

Summary

MediaWiki is the software used for Wikipedia and the other Wikimedia

Foundation websites. Compared to other wikis, it has an excellent

range of features and support for high-traffic websites using multiple

servers

This package supports wiki farms. Copy /var/www/wiki over to the

desired wiki location and configure it through the web

interface. Remember to remove the config dir after completing the

configuration.

Update Information:

This update upgrades mediawiki code to 1.15.1 and fixes some path references. Upstream comments: This is a security and bugfix release of MediaWiki 1.15.1 and 1.14.1. A cross-site scripting (XSS) vulnerability was discovered. Only versions 1.14.0, 1.15.0 and release candidates for those releases are affected.

Change Log

* Mon Jul 13 2009 Axel Thimm - 1.15.1-48 - Update to 1.15.1 (Fixes XSS vulnerability). * Sat Jul 11 2009 Axel Thimm - 1.15.0-47 - Fix api.php breakage. * Sat Jun 13 2009 Axel Thimm - 1.15.0-46 - Update to 1.15.0. * Thu Apr 16 2009 S390x secondary arch maintainer - ExcludeArch sparc64, s390, s390x as we don't have OCaml on those archs (added sparc64 per request from the sparc maintainer) * Sat Feb 28 2009 Axel Thimm - 1.14.0-45 - Update to 1.14.0. * Sun Feb 22 2009 Axel Thimm - 1.13.4-44 - Split package up, so some users can decide to not install math support (results in smaller installs), see RH bug #485447. * Wed Feb 18 2009 Axel Thimm - 1.13.4-43 - Update to 1.13.4, closes RH bug #485728. * Tue Dec 23 2008 Axel Thimm - 1.13.3-42 - Update to 1.13.3, closes RH bug #476621 (CVE-2008-5249, CVE-2008-5250, CVE-2008-5252 and CVE-2008-5687, CVE-2008-5688)

References

[ 1 ] Bug #484855 - mediawiki api.php has bad path https://bugzilla.redhat.com/show_bug.cgi?id=484855 [ 2 ] Bug #494362 - maintenance scripts fail https://bugzilla.redhat.com/show_bug.cgi?id=494362 [ 3 ] Bug #494880 - Uploading fails https://bugzilla.redhat.com/show_bug.cgi?id=494880

Update Instructions

This update can be installed with the "yum" update program. Use su -c 'yum update mediawiki' at the command line. For more information, refer to "Managing Software with yum", available at .

Severity
Name : mediawiki
Product : Fedora 10
Version : 1.15.1
Release : 48.fc10
URL : https://www.mediawiki.org/wiki/MediaWiki
Summary : A wiki engine

Related News