Note: This is a public test instance of Red Hat Bugzilla. The data contained within is a snapshot of the live data so any changes you make will not be reflected in the production Bugzilla. Email is disabled so feel free to test any aspect of the site that you want. File any problems you find or give feedback at bugzilla.redhat.com.
Bug 1052913 - New mediawiki security releases have been released
Summary: New mediawiki security releases have been released
Keywords:
Status: CLOSED ERRATA
Alias: None
Product: Fedora EPEL
Classification: Fedora
Component: mediawiki
Version: el5
Hardware: Unspecified
OS: Unspecified
unspecified
unspecified
Target Milestone: ---
Assignee: Dan Mashal
QA Contact: Fedora Extras Quality Assurance
URL:
Whiteboard:
Depends On: 1052874
Blocks:
TreeView+ depends on / blocked
 
Reported: 2014-01-14 11:44 UTC by Patrick Uiterwijk
Modified: 2014-02-16 11:21 UTC (History)
4 users (show)

Fixed In Version: mediawiki119-1.19.11-2.el5
Doc Type: Bug Fix
Doc Text:
Clone Of: 1052874
Environment:
Last Closed: 2014-02-16 11:21:18 UTC
Type: Bug
Embargoed:


Attachments (Terms of Use)

Description Patrick Uiterwijk 2014-01-14 11:44:23 UTC
+++ This bug was initially created as a clone of Bug #1052874 +++

New versions:
1.19.10
1.21.4
1.22.1


Bugs fixed:
- (bug 57550) (CVE-2013-6452) SECURITY: Disallow stylesheets in SVG Uploads
- (bug 58088) (CVE-2013-6451) SECURITY: Don't normalize U+FF3C to \ in CSS Checks
- (bug 58472) (CVE-2013-6454) SECURITY: Disallow -o-link in styles
- (bug 58553) (CVE-2013-6453) SECURITY: Return error on invalid XML for SVG Uploads
- (bug 58699) (CVE-2013-6472) SECURITY: Fix RevDel log entry information leaks

Comment 1 Dan Mashal 2014-01-24 07:48:52 UTC
Sorry for the late response. The new source is vastly different from the old one (last updated 4 years ago). Will try and get something done tomorrow.

Comment 2 Fedora Update System 2014-01-29 00:03:07 UTC
mediawiki119-1.19.11-2.el5 has been submitted as an update for Fedora EPEL 5.
https://admin.fedoraproject.org/updates/mediawiki119-1.19.11-2.el5

Comment 3 Patrick Uiterwijk 2014-01-29 00:05:28 UTC
This issue has been fixed in mediawiki119.

For the purpose of not doing any major upgrades to packages in EPEL, we have decided to branch mediawiki119 for el5 as well, to keep it up-to-date with security updates.

Comment 4 Fedora Update System 2014-01-29 21:24:40 UTC
Package mediawiki119-1.19.11-2.el5:
* should fix your issue,
* was pushed to the Fedora EPEL 5 testing repository,
* should be available at your local mirror within two days.
Update it with:
# su -c 'yum update --enablerepo=epel-testing mediawiki119-1.19.11-2.el5'
as soon as you are able to.
Please go to the following url:
https://admin.fedoraproject.org/updates/FEDORA-EPEL-2014-0400/mediawiki119-1.19.11-2.el5
then log in and leave karma (feedback).

Comment 5 Fedora Update System 2014-02-16 11:21:18 UTC
mediawiki119-1.19.11-2.el5 has been pushed to the Fedora EPEL 5 stable repository.  If problems still persist, please make note of it in this bug report.


Note You need to log in before you can comment on or make changes to this bug.