Bug 1052913

Summary: New mediawiki security releases have been released
Product: [Fedora] Fedora EPEL Reporter: Patrick Uiterwijk <puiterwijk>
Component: mediawikiAssignee: Dan Mashal <dan.mashal>
Status: CLOSED ERRATA QA Contact: Fedora Extras Quality Assurance <extras-qa>
Severity: unspecified Docs Contact:
Priority: unspecified    
Version: el5CC: dan.mashal, gwync, mike, puiterwijk
Target Milestone: ---   
Target Release: ---   
Hardware: Unspecified   
OS: Unspecified   
Whiteboard:
Fixed In Version: mediawiki119-1.19.11-2.el5 Doc Type: Bug Fix
Doc Text:
Story Points: ---
Clone Of: 1052874 Environment:
Last Closed: 2014-02-16 11:21:18 UTC Type: Bug
Regression: --- Mount Type: ---
Documentation: --- CRM:
Verified Versions: Category: ---
oVirt Team: --- RHEL 7.3 requirements from Atomic Host:
Cloudforms Team: --- Target Upstream Version:
Embargoed:
Bug Depends On: 1052874    
Bug Blocks: 1052962    

Description Patrick Uiterwijk 2014-01-14 11:44:23 UTC
+++ This bug was initially created as a clone of Bug #1052874 +++

New versions:
1.19.10
1.21.4
1.22.1


Bugs fixed:
- (bug 57550) (CVE-2013-6452) SECURITY: Disallow stylesheets in SVG Uploads
- (bug 58088) (CVE-2013-6451) SECURITY: Don't normalize U+FF3C to \ in CSS Checks
- (bug 58472) (CVE-2013-6454) SECURITY: Disallow -o-link in styles
- (bug 58553) (CVE-2013-6453) SECURITY: Return error on invalid XML for SVG Uploads
- (bug 58699) (CVE-2013-6472) SECURITY: Fix RevDel log entry information leaks

Comment 1 Dan Mashal 2014-01-24 07:48:52 UTC
Sorry for the late response. The new source is vastly different from the old one (last updated 4 years ago). Will try and get something done tomorrow.

Comment 2 Fedora Update System 2014-01-29 00:03:07 UTC
mediawiki119-1.19.11-2.el5 has been submitted as an update for Fedora EPEL 5.
https://admin.fedoraproject.org/updates/mediawiki119-1.19.11-2.el5

Comment 3 Patrick Uiterwijk 2014-01-29 00:05:28 UTC
This issue has been fixed in mediawiki119.

For the purpose of not doing any major upgrades to packages in EPEL, we have decided to branch mediawiki119 for el5 as well, to keep it up-to-date with security updates.

Comment 4 Fedora Update System 2014-01-29 21:24:40 UTC
Package mediawiki119-1.19.11-2.el5:
* should fix your issue,
* was pushed to the Fedora EPEL 5 testing repository,
* should be available at your local mirror within two days.
Update it with:
# su -c 'yum update --enablerepo=epel-testing mediawiki119-1.19.11-2.el5'
as soon as you are able to.
Please go to the following url:
https://admin.fedoraproject.org/updates/FEDORA-EPEL-2014-0400/mediawiki119-1.19.11-2.el5
then log in and leave karma (feedback).

Comment 5 Fedora Update System 2014-02-16 11:21:18 UTC
mediawiki119-1.19.11-2.el5 has been pushed to the Fedora EPEL 5 stable repository.  If problems still persist, please make note of it in this bug report.