-----BEGIN PGP SIGNED MESSAGE-----
Hash: SHA1
MediaWiki 1.4beta5 is a security and bug fix release for the 1.4 beta
series. Previous MediaWiki 1.4 beta releases include an input
validation error which could lead to execution of arbitrary PHP code on
the server.
All users of 1.4 beta releases are strongly urged to upgrade to
1.4beta5 immediately. The 1.3.x stable release series is not affected
by this problem.
Beta 5 additionally fixes a number of non-security-related bugs, and
requires one minor database change. If upgrading from a previous beta,
see the file UPGRADE in the release archive for instructions.
Bugs fixed in beta 5:
* (bug 1124) Fix ImageGallery XHTML compliance
* (bug 1186) news: in the middle of a word
* (bug 1283) Use underlining and borders to highlight
additions/deletions
in diff-view
* Use user's local timezone in Special:Log display
* Show filename for images in gallery by default (restore beta 3
behaviour)
* (bug 1201) Double-escaping in brokenlinks, imagelinks, categorylinks,
searchindex
* When using squid reverse proxy, cache the redirect to the Main_Page
* (bug 1302) Fix Norwegian language file
* (bug 1205) Fix broken article saving in PHP 5.1
* (bug 1206) Implement CURRENTWEEK and CURRENTDOW magic keyword (will
give
number of the week and number of the day).
* (bug 1204) Blocks do not expire automatically
* (bug 1184) expiry time of indefinite blocks shown as the current time
* (bug 1317) Fix external links in image captions
* (bug 1084) Fix logo not rendering centrally in IE
* (bug 288) Fix tabs wrapping in IE6
* (bug 119) Fix full-width tabs with RTL text in IE
* (bug 1323) Fix logo rendering off-screen in IE with RTL language
* Show "block" link in Special:Recentchanges for logged in users, too,
if
wgUserSysopBans is true.
* (bug 1326) Use content language for '1movedto2' in edit history
* zh: Fix warning when HTTP_ACCEPT_LANGUAGE is not set
* zh: Fix double conversion for zh-sg and zh-hk
* (bug 1132) Fix concatenation of link lists in refreshLinks
* (bug 1101) Fix memory leak in refreshLinks
* (bug 1339) Fix order of @imports in Cologne Blue CSS
* Don't try to create links without namespaces ([[Category:]] link bug)
* Memcached data compression fixes
* Several valid XHTML fixes
* (bug 624) Fix IE freezing rendering whilst waiting for CSS with
MonoBook
* (bug 211) Fix tabbed preferences with XHTML MIME type
* Fix for script execution vulnerability.
Due to a temporary problem with SourceForge's file release system, this
release is currently hosted on Wikimedia's servers instead of the usual
location.
Release notes:
http://zwinger.wikimedia.org/mediawiki/RELEASE-NOTES
Download:
http://zwinger.wikimedia.org/mediawiki/mediawiki-1.4beta5.tar.gz
MD5 checksum: 11342e291b5af4e8d4668ad5c3a6d171
SHA1 checksum: 23178fdba265083186c6475a0c3d0ea4d2e06ae0
Wiki admin help mailing list:
http://mail.wikipedia.org/mailman/listinfo/mediawiki-l
Low-traffic release announcements mailing list:
http://mail.wikipedia.org/mailman/listinfo/mediawiki-announce
Bug report system:
http://bugzilla.wikipedia.org/
Play "stump the developers" live on IRC:
#mediawiki on irc.freenode.net
- -- brion vibber (brion @ pobox.com)
-----BEGIN PGP SIGNATURE-----
Version: GnuPG v1.2.6 (Darwin)
iD8DBQFB64dDwRnhpk1wk44RArTfAKCtGNLWbDAz/2MQvaQDnyoYdZ9SAwCdELJn
YmxnTCkN8fULr1tPi9MMnYw=
=YaNq
-----END PGP SIGNATURE-----
-----BEGIN PGP SIGNED MESSAGE-----
Hash: SHA1
MediaWiki 1.4beta4 is an experimental release, to help flush out
remaining major problems in the code prior to a final public 1.4.0
release. It is not recommended to use this beta on a public site unless
you're familiar with MediaWiki innards and are willing and able to help
diagnose and fix problems that come up.
Users of the earlier beta releases should upgrade to keep up with bug
fixes. Anyone running a version _earlier_ than beta 3 should upgrade
immediately if uploads are enabled due to potential security
vulnerabilities on some Apache configurations.
=== Beta 4 fixes ===
* (bug 1090) Fix sitesupport links in CB/classic skins
* Gracefully ignore non-legal titles in a <gallery>
* Fix message page caching behavior when $wgCapitalLinks is turned off
after installation and the wiki is subsequently upgraded
* Database error messages include the database server name/address
* Paging support for large categories
* Fix image page scaling when thumbnail generation is disabled
* Select the content language in prefs when bogus interface language is
set
* Fix interwiki links in edit comments
* Fix crash on banned user visit
* Avoid PHP warning messages when thumbnail not generated
* (bug 1157) List unblocks correctly in Special:Log
* Fix fatal errors in LanguageLi.php
* Undo overly bright, difficult to read colors in Cologne Blue
* (bug 1162) fix five-tilde date inserter
* Add raw signatures option for those who simply must have cute sigs
* (bug 1164) Let wikitext be used in Loginprompt and Loginend messages
* Add the dreaded <span> to the HTML whitelist
* (bug 1170) Fix Russian linktrail
* (bug 1168) Missing text on the bureaucrat log
* (bug 1180) Fix Makesysop on shared-user-table sites
* (bug 1178) Fix previous diff link when using 'oldid=0'
* (bug 1173) Stop blocked accounts from reverting/deleting images
* Keep generated stylesheets cache-separated for each user
* (bug 1175) Fix "preview on first edit" mode
* Fix revert bug caused by bug 1175 fix
* Fix CSS classes on minor, new, unpatrolled markers in enhanced RC
* Set MySQL 4 boolean search back to 'and' mode by default
* (bug 1193) Fix move-only page protection mode
* Fix zhtable Makefile to include the traditional manual table
* Add memcache timeout for the zh conversion tables
* Allow user customization of the zh conversion tables through
Mediawiki:zhconversiontable
* Add zh-min-man (back) to language names list
* Ported $wgCopyrightIcon setting from REL1_3A
* (bug 1218) Show the original image on image pages if the thumbnail
would be
bigger than the original image
* (bug 1213) i18n of Special:Log labels
* (bug 1013) Fix jbo, minnan in language names list
* Added magic word MAG_NOTITLECONVERT to indicate that the title of the
page
do not need to be converted. Useful in zh:
* (bug 1224) Use proper date messages for date reformatter
* (bug 1241) Don't show 'cont.' for first entry of the category list
* (bug 1240) Special:Preferences was broken in Slovenian locale when
$wgUseDynamicDates is enabled
* Added magic word MAG_NOCONTENTCONVERT to supress the conversion of the
content of an article. Useful in zh:
* write-lock for updating the zh conversion tables in memcache
* recursively parse subpages of MediaWiki:Zhconversiontable
* (bug 1144) Fix export for fy language
* make removal of an entry from zhconversiontable work
* (bug 752) Don't insert newline in link title for url with %0a
* Fix missing search box contents in MonoBook skin
* Add option to forward search directly to an external URL (eg google)
* Correctly highlight the fallback language variant when the selected
variant is disabled. Used in zh: only for now.
Release notes:
http://sourceforge.net/project/shownotes.php?release_id=295298
Download:
http://prdownloads.sf.net/wikipedia/mediawiki-1.4beta4.tar.gz?download
Wiki admin help mailing list:
http://mail.wikipedia.org/mailman/listinfo/mediawiki-l
Low-traffic release announcements mailing list:
http://mail.wikipedia.org/mailman/listinfo/mediawiki-announce
Bug report system:
http://bugzilla.wikipedia.org/
Play "stump the developers" live on IRC:
#mediawiki on irc.freenode.net
- -- brion vibber (brion @ pobox.com)
-----BEGIN PGP SIGNATURE-----
Version: GnuPG v1.2.6 (Darwin)
iD8DBQFB3zGFwRnhpk1wk44RAuB/AKCWvLqX6Yl6JKY5AYlEkllyCPU/ZACfda3Z
ebLrrXyDG6roJzxW5bWdoYo=
=uvCv
-----END PGP SIGNATURE-----