+++ This bug was initially created as a clone of Bug #1052874 +++ New versions: 1.19.10 1.21.4 1.22.1 Bugs fixed: - (bug 57550) (CVE-2013-6452) SECURITY: Disallow stylesheets in SVG Uploads - (bug 58088) (CVE-2013-6451) SECURITY: Don't normalize U+FF3C to \ in CSS Checks - (bug 58472) (CVE-2013-6454) SECURITY: Disallow -o-link in styles - (bug 58553) (CVE-2013-6453) SECURITY: Return error on invalid XML for SVG Uploads - (bug 58699) (CVE-2013-6472) SECURITY: Fix RevDel log entry information leaks
Sorry for the late response. The new source is vastly different from the old one (last updated 4 years ago). Will try and get something done tomorrow.
mediawiki119-1.19.11-2.el5 has been submitted as an update for Fedora EPEL 5. https://admin.fedoraproject.org/updates/mediawiki119-1.19.11-2.el5
This issue has been fixed in mediawiki119. For the purpose of not doing any major upgrades to packages in EPEL, we have decided to branch mediawiki119 for el5 as well, to keep it up-to-date with security updates.
Package mediawiki119-1.19.11-2.el5: * should fix your issue, * was pushed to the Fedora EPEL 5 testing repository, * should be available at your local mirror within two days. Update it with: # su -c 'yum update --enablerepo=epel-testing mediawiki119-1.19.11-2.el5' as soon as you are able to. Please go to the following url: https://admin.fedoraproject.org/updates/FEDORA-EPEL-2014-0400/mediawiki119-1.19.11-2.el5 then log in and leave karma (feedback).
mediawiki119-1.19.11-2.el5 has been pushed to the Fedora EPEL 5 stable repository. If problems still persist, please make note of it in this bug report.