Hello everyone,
I would like to announce the release of MediaWiki 1.19.20, 1.22.12 and 1.23.5. This is a security release. Download links are given at the end of this email.
== Security == * (bug 70672) SECURITY: OutputPage: Remove separation of css and js module allowance.
Full release notes for 1.23.5: https://www.mediawiki.org/wiki/Release_notes/1.23
Full release notes for 1.22.12: https://www.mediawiki.org/wiki/Release_notes/1.22
Full release notes for 1.19.20: https://www.mediawiki.org/wiki/Release_notes/1.19
Public keys: https://www.mediawiki.org/keys/keys.html
********************************************************************** 1.23.5 ********************************************************************** Download: https://releases.wikimedia.org/mediawiki/1.23/mediawiki-1.23.5.tar.gz
Patch to previous version (1.23.4): https://releases.wikimedia.org/mediawiki/1.23/mediawiki-1.23.5.patch.gz
GPG signatures: https://releases.wikimedia.org/mediawiki/1.23/mediawiki-core-1.23.5.tar.gz.s... https://releases.wikimedia.org/mediawiki/1.23/mediawiki-1.23.5.tar.gz.sig https://releases.wikimedia.org/mediawiki/1.23/mediawiki-1.23.5.patch.gz.sig
Note: There is no i18n patch as there are no changes in translation.
********************************************************************** 1.22.12 ********************************************************************** Download: https://releases.wikimedia.org/mediawiki/1.22/mediawiki-1.22.12.tar.gz
Patch to previous version (1.22.11): https://releases.wikimedia.org/mediawiki/1.22/mediawiki-1.22.12.patch.gz
GPG signatures: https://releases.wikimedia.org/mediawiki/1.22/mediawiki-core-1.22.12.tar.gz.... https://releases.wikimedia.org/mediawiki/1.22/mediawiki-1.22.12.tar.gz.sig https://releases.wikimedia.org/mediawiki/1.22/mediawiki-1.22.12.patch.gz.sig
Note: There is no i18n patch as there are no changes in translation.
********************************************************************** 1.19.20 ********************************************************************** Download: https://releases.wikimedia.org/mediawiki/1.19/mediawiki-1.19.20.tar.gz
Patch to previous version (1.19.19): https://releases.wikimedia.org/mediawiki/1.19/mediawiki-1.19.20.patch.gz
GPG signatures: https://releases.wikimedia.org/mediawiki/1.19/mediawiki-core-1.19.20.tar.gz.... https://releases.wikimedia.org/mediawiki/1.19/mediawiki-1.19.20.tar.gz.sig https://releases.wikimedia.org/mediawiki/1.19/mediawiki-1.19.20.patch.gz.sig
Note: There is no i18n patch as there are no changes in translation.
Markus Glaser (Wiki Release Team)
On 10/1/14, Markus Glaser glaser@hallowelt.biz wrote:
Hello everyone,
I would like to announce the release of MediaWiki 1.19.20, 1.22.12 and 1.23.5. This is a security release. Download links are given at the end of this email.
== Security ==
- (bug 70672) SECURITY: OutputPage: Remove separation of css and js module
allowance.
Hmm. Lots of third parties use CSS in MediaWiki:Common.css to make significant theming customizations without making a "real" skin. Perhaps the release notes should mention that users who do this will have their log in page suddenly look out of place.
Given that this change really only makes it mildly harder for a novice attacker to do something evil, and there exists potential use cases it breaks perhaps it should be behind a config variable defaulting to the more secure setting. (A moderately skilled attacker should easily be able to think of ways around this to steal users passwords. Once an attacker can get javascript inserted, its pretty much game over. Trying to "limit" damage of a malicious user modifying site js, is like trying to unbreak an egg. Once the egg is broken, well you know the story about humpty dumpty)
--bawolff
wikitech-l@lists.wikimedia.org