MediaWiki 1.15.2 - Another Web Company
ArcadeDownloadsNewslettersForum MenuNavigationWhat AWC OffersWiki ToolsLogin or Create Account

Log in

You must have cookies enabled to log in to Main Site - Local.

 

MediaWiki 1.15.2

From Another Web Company

Viewed 510 times, With a total of 2 Posts
Have a suggestion, improvement, change or non-beta Forum Entension bug ? Please add them to the todo list

Forum Vet
Wiki Edits: 2898
Threads 135
Posts 1397
-

http://www.mediawiki.org/wiki/Download




This is a security and bugfix release of MediaWiki 1.15.2.

Two security issues were discovered:

A CSS validation issue was discovered which allows editors to display
external images in wiki pages. This is a privacy concern on public
wikis, since a malicious user may link to an image on a server they
control, which would allow that attacker to gather IP addresses and
other information from users of the public wiki. All sites running
publicly-editable MediaWiki installations are advised to upgrade. All
versions of MediaWiki (prior to this one) are affected.

A data leakage vulnerability was discovered in thumb.php which affects
wikis which restrict access to private files using img_auth.php, or
some similar scheme. All versions of MediaWiki since 1.5 are affected.

Deleting thumb.php is a suitable workaround for private wikis which do
not use $wgThumbnailScriptPath or $wgLocalRepo['thumbScriptUrl'].
Alternatively, you can upgrade to MediaWiki 1.15.2 or backport the
patch below to whatever version of MediaWiki you are using.

MediaWiki is not compatible with PHP 5.3.1 due to a bug in that
release, which is fixed in PHP 5.3.2. This release of MediaWiki will
refuse to upgrade if an affected version of PHP is present. Note that
local or distribution-specific backports of the PHP bug fix are
supported. See http://bugs.php.net/50394 for details.

Full release notes:
http://svn.wikimedia.org/svnroot/mediawiki/tags/REL1_15_2/phase3/RELEASE-NOTES
~ What was once an opinion, became a fact, to be later proven wrong ~
  • Forum Ver. 2.5.10 has been released (6/19/2010), Download here.


Clicked A Few Times
Wiki Edits: 5
Threads 7
Posts 63
Thanks, just updated.
Was kinda hoping that finally the quarterly release came but noooo :P
Wonder what happened to that...ah well, i'll wait.

But thanks for the notice, i gave up checking the MW site for updates
What's the difference between a duck ? O.o

Forum Vet
Wiki Edits: 2898
Threads 135
Posts 1397
Glad it helped.
Somewhere on the MW site there's a place to subscribe via email for releases like this.


Forum Image:Icon-double-arrow.gif AWC's Corner Image:Icon-double-arrow.gif MISC MediaWiki



Whos here now: Members 0 Guests 0 Bots/Crawlers: 1


AWC's: 2.6.0 MediaWiki - Stand Alone Forum Extension
Forum theme style by: AWC