Bug 1052913 - New mediawiki security releases have been released
Summary: New mediawiki security releases have been released
Alias: None
Product: Fedora EPEL
Classification: Fedora
Component: mediawiki
Version: el5
Hardware: Unspecified
OS: Unspecified
Target Milestone: ---
Assignee: Dan Mashal
QA Contact: Fedora Extras Quality Assurance
Depends On: 1052874
Blocks: CVE-2013-6451, CVE-2013-6452, CVE-2013-6453, CVE-2013-6454, CVE-2013-6472
TreeView+ depends on / blocked
Reported: 2014-01-14 11:44 UTC by Patrick Uiterwijk
Modified: 2014-02-16 11:21 UTC (History)
4 users (show)

Fixed In Version: mediawiki119-1.19.11-2.el5
Doc Type: Bug Fix
Doc Text:
Clone Of: 1052874
Last Closed: 2014-02-16 11:21:18 UTC
Type: Bug

Attachments (Terms of Use)

Description Patrick Uiterwijk 2014-01-14 11:44:23 UTC
+++ This bug was initially created as a clone of Bug #1052874 +++

New versions:

Bugs fixed:
- (bug 57550) (CVE-2013-6452) SECURITY: Disallow stylesheets in SVG Uploads
- (bug 58088) (CVE-2013-6451) SECURITY: Don't normalize U+FF3C to \ in CSS Checks
- (bug 58472) (CVE-2013-6454) SECURITY: Disallow -o-link in styles
- (bug 58553) (CVE-2013-6453) SECURITY: Return error on invalid XML for SVG Uploads
- (bug 58699) (CVE-2013-6472) SECURITY: Fix RevDel log entry information leaks

Comment 1 Dan Mashal 2014-01-24 07:48:52 UTC
Sorry for the late response. The new source is vastly different from the old one (last updated 4 years ago). Will try and get something done tomorrow.

Comment 2 Fedora Update System 2014-01-29 00:03:07 UTC
mediawiki119-1.19.11-2.el5 has been submitted as an update for Fedora EPEL 5.

Comment 3 Patrick Uiterwijk 2014-01-29 00:05:28 UTC
This issue has been fixed in mediawiki119.

For the purpose of not doing any major upgrades to packages in EPEL, we have decided to branch mediawiki119 for el5 as well, to keep it up-to-date with security updates.

Comment 4 Fedora Update System 2014-01-29 21:24:40 UTC
Package mediawiki119-1.19.11-2.el5:
* should fix your issue,
* was pushed to the Fedora EPEL 5 testing repository,
* should be available at your local mirror within two days.
Update it with:
# su -c 'yum update --enablerepo=epel-testing mediawiki119-1.19.11-2.el5'
as soon as you are able to.
Please go to the following url:
then log in and leave karma (feedback).

Comment 5 Fedora Update System 2014-02-16 11:21:18 UTC
mediawiki119-1.19.11-2.el5 has been pushed to the Fedora EPEL 5 stable repository.  If problems still persist, please make note of it in this bug report.

Note You need to log in before you can comment on or make changes to this bug.