<?xml version="1.0" encoding="UTF-8"?>
<rdf:RDF xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns="http://purl.org/rss/1.0/" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:syn="http://purl.org/rss/1.0/modules/syndication/" xmlns:admin="http://webns.net/mvcb/">
  <channel rdf:about="http://permalink.gmane.org/gmane.org.wikimedia.mediawiki.announce">
    <title>gmane.org.wikimedia.mediawiki.announce</title>
    <link>http://permalink.gmane.org/gmane.org.wikimedia.mediawiki.announce</link>
    <description/>
    <syn:updatePeriod>hourly</syn:updatePeriod>
    <syn:updateFrequency>1</syn:updateFrequency>
    <syn:updateBase>1901-01-01T00:00+00:00</syn:updateBase>
    <items>
      <rdf:Seq>
        <rdf:li rdf:resource="http://permalink.gmane.org/gmane.org.wikimedia.mediawiki.announce/196"/>
        <rdf:li rdf:resource="http://permalink.gmane.org/gmane.org.wikimedia.mediawiki.announce/195"/>
        <rdf:li rdf:resource="http://permalink.gmane.org/gmane.org.wikimedia.mediawiki.announce/194"/>
        <rdf:li rdf:resource="http://permalink.gmane.org/gmane.org.wikimedia.mediawiki.announce/193"/>
        <rdf:li rdf:resource="http://permalink.gmane.org/gmane.org.wikimedia.mediawiki.announce/192"/>
        <rdf:li rdf:resource="http://permalink.gmane.org/gmane.org.wikimedia.mediawiki.announce/191"/>
        <rdf:li rdf:resource="http://permalink.gmane.org/gmane.org.wikimedia.mediawiki.announce/190"/>
        <rdf:li rdf:resource="http://permalink.gmane.org/gmane.org.wikimedia.mediawiki.announce/189"/>
        <rdf:li rdf:resource="http://permalink.gmane.org/gmane.org.wikimedia.mediawiki.announce/188"/>
        <rdf:li rdf:resource="http://permalink.gmane.org/gmane.org.wikimedia.mediawiki.announce/187"/>
        <rdf:li rdf:resource="http://permalink.gmane.org/gmane.org.wikimedia.mediawiki.announce/186"/>
        <rdf:li rdf:resource="http://permalink.gmane.org/gmane.org.wikimedia.mediawiki.announce/185"/>
        <rdf:li rdf:resource="http://permalink.gmane.org/gmane.org.wikimedia.mediawiki.announce/184"/>
        <rdf:li rdf:resource="http://permalink.gmane.org/gmane.org.wikimedia.mediawiki.announce/183"/>
        <rdf:li rdf:resource="http://permalink.gmane.org/gmane.org.wikimedia.mediawiki.announce/182"/>
        <rdf:li rdf:resource="http://permalink.gmane.org/gmane.org.wikimedia.mediawiki.announce/181"/>
        <rdf:li rdf:resource="http://permalink.gmane.org/gmane.org.wikimedia.mediawiki.announce/180"/>
        <rdf:li rdf:resource="http://permalink.gmane.org/gmane.org.wikimedia.mediawiki.announce/179"/>
        <rdf:li rdf:resource="http://permalink.gmane.org/gmane.org.wikimedia.mediawiki.announce/178"/>
        <rdf:li rdf:resource="http://permalink.gmane.org/gmane.org.wikimedia.mediawiki.announce/177"/>
      </rdf:Seq>
    </items>
    <image rdf:resource="http://gmane.org/img/gmane-25t.png"/>
    <textinput rdf:resource=""/>
  </channel>
  <image rdf:about="http://gmane.org/img/gmane-25t.png">
    <title>Gmane</title>
    <url>http://gmane.org/img/gmane-25t.png</url>
    <link>http://gmane.org</link>
  </image>
  <item rdf:about="http://permalink.gmane.org/gmane.org.wikimedia.mediawiki.announce/196">
    <title>MediaWiki Security Release: 1.20.5 and 1.19.6</title>
    <link>http://permalink.gmane.org/gmane.org.wikimedia.mediawiki.announce/196</link>
    <description>&lt;pre&gt;I would like to announce the release of MediaWiki 1.20.5 and 1.19.6.
These releases fix 2 security related issues that could affect users
of MediaWiki. Download links are given at the end of this email.

* Jan Schejbal / Hatforce.com reported that SVG script filtering could
be bypassed for Chrome and Firefox clients by using an encoding that
MediaWiki understood, but these browsers interpreted as UTF-8.
&amp;lt;https://bugzilla.wikimedia.org/show_bug.cgi?id=47304&amp;gt;

* Internal review discovered that extensions were not given the
opportunity to disable a password reset, which could lead to
circumvention of two-factor authentication.
&amp;lt;https://bugzilla.wikimedia.org/show_bug.cgi?id=46590&amp;gt;

Full release notes for 1.20.5:
&amp;lt;https://www.mediawiki.org/wiki/Release_notes/1.20&amp;gt;

Full release notes for 1.19.6:
&amp;lt;https://www.mediawiki.org/wiki/Release_notes/1.19&amp;gt;

For information about how to upgrade, see
&amp;lt;https://www.mediawiki.org/wiki/Manual:Upgrading&amp;gt;


**********************************************************************
  &lt;/pre&gt;</description>
    <dc:creator>Chris Steipp</dc:creator>
    <dc:date>2013-04-30T20:14:43</dc:date>
  </item>
  <item rdf:about="http://permalink.gmane.org/gmane.org.wikimedia.mediawiki.announce/195">
    <title>Pre-Release Announcement for MediaWiki 1.19.6and 1.20.5</title>
    <link>http://permalink.gmane.org/gmane.org.wikimedia.mediawiki.announce/195</link>
    <description>&lt;pre&gt;This is a notice that on Tuesday, April 30th between 20:00-21:00 UTC
(1-2pm PDT) Wikimedia Foundation will release security updates for
current and supported branches of the MediaWiki software. Downloads
and patches will be available at that time, with the git repositories
updated later that afternoon.

_______________________________________________
MediaWiki announcements mailing list
To unsubscribe, go to:
https://lists.wikimedia.org/mailman/listinfo/mediawiki-announce
&lt;/pre&gt;</description>
    <dc:creator>Chris Steipp</dc:creator>
    <dc:date>2013-04-29T20:14:16</dc:date>
  </item>
  <item rdf:about="http://permalink.gmane.org/gmane.org.wikimedia.mediawiki.announce/194">
    <title>MediaWiki Security Release: 1.20.4 and 1.19.5</title>
    <link>http://permalink.gmane.org/gmane.org.wikimedia.mediawiki.announce/194</link>
    <description>&lt;pre&gt;I would like to announce the release of MediaWiki 1.20.4 and 1.19.5.
These releases fix 3 security related bugs that could affect users of
MediaWiki. Download links are given at the end of this email.

* An internal review discovered that specially crafted Lua function
names could lead to XSS.
&amp;lt;https://bugzilla.wikimedia.org/show_bug.cgi?id=46084&amp;gt;

* Daniel Franke reported that during SVG parsing, MediaWiki failed to
prevent XML external entity (XXE) processing. This could lead to local
file disclosure, or potentially remote command execution in
environments that have enabled expect:// handling.
&amp;lt;https://bugzilla.wikimedia.org/show_bug.cgi?id=46859&amp;gt;

* Internal review also discovered that Special:Import, and
Extension:RSS failed to prevent XML external entity (XXE) processing.
&amp;lt;https://bugzilla.wikimedia.org/show_bug.cgi?id=47251&amp;gt;


Full release notes for 1.20.4:
&amp;lt;https://www.mediawiki.org/wiki/Release_notes/1.20&amp;gt;

Full release notes for 1.19.5:
&amp;lt;https://www.mediawiki.org/wiki/Release_notes/1.19&amp;gt;

For inform&lt;/pre&gt;</description>
    <dc:creator>Chris Steipp</dc:creator>
    <dc:date>2013-04-15T20:37:29</dc:date>
  </item>
  <item rdf:about="http://permalink.gmane.org/gmane.org.wikimedia.mediawiki.announce/193">
    <title>Pre-Release Announcement for MediaWiki 1.19.5and 1.20.4</title>
    <link>http://permalink.gmane.org/gmane.org.wikimedia.mediawiki.announce/193</link>
    <description>&lt;pre&gt;This is a notice that on Monday, April 15th between 20:00-21:00 UTC
(1-2pm PDT) Wikimedia Foundation will release security updates for
current and supported branches of the MediaWiki software. Downloads
and patches will be available at that time, with the git repositories
updated later that afternoon. CVSS scores are between 4.3 and 7.1,
most users will want to update.

_______________________________________________
MediaWiki announcements mailing list
To unsubscribe, go to:
https://lists.wikimedia.org/mailman/listinfo/mediawiki-announce
&lt;/pre&gt;</description>
    <dc:creator>Chris Steipp</dc:creator>
    <dc:date>2013-04-12T22:09:40</dc:date>
  </item>
  <item rdf:about="http://permalink.gmane.org/gmane.org.wikimedia.mediawiki.announce/192">
    <title>MediaWiki security release: 1.20.3 and 1.19.4</title>
    <link>http://permalink.gmane.org/gmane.org.wikimedia.mediawiki.announce/192</link>
    <description>&lt;pre&gt;I would like to announce the release of MediaWiki 1.20.3 and 1.19.4.
These releases fix 3 security related bugs that could affect users of
MediaWiki. Download links are given at the end of this email.

* By default, the curl library passed 'true' to CURLOPT_SSL_VERIFYHOST
when establishing an SSL connection, instead of '2'.
&amp;lt;https://bugzilla.wikimedia.org/show_bug.cgi?id=44135&amp;gt;
&amp;lt;https://bugzilla.wikimedia.org/show_bug.cgi?id=42441&amp;gt;

* MediaWiki developer Krenair discovered that the full user object,
including password hash, could be returned when unblocking a user by
the API. Exploitation of this vulnerability requires the user to have
permissions to unblock users, by default this is limited to users in
the sysop group.
&amp;lt;https://bugzilla.wikimedia.org/show_bug.cgi?id=43518&amp;gt;

* MediaWiki developer Platonides discovered that the maintenance
script mwdoc-filter.php did not check if it was being run via the CLI,
and could allow an attacker to read arbitrary files if PHP's
register_globals was enabled and the .ht&lt;/pre&gt;</description>
    <dc:creator>Chris Steipp</dc:creator>
    <dc:date>2013-03-04T19:19:22</dc:date>
  </item>
  <item rdf:about="http://permalink.gmane.org/gmane.org.wikimedia.mediawiki.announce/191">
    <title>Pre-Release Announcement for MediaWiki 1.19.4and 1.20.3</title>
    <link>http://permalink.gmane.org/gmane.org.wikimedia.mediawiki.announce/191</link>
    <description>&lt;pre&gt;This is a notice to let you know that on Monday, March 4th between
21:00-22:00 UTC (1-2pm PST) Wikimedia Foundation will release security
updates for current and supported branches of the MediaWiki software.
Downloads and patches will be available at that time, with the git
repositories updated later that afternoon.

_______________________________________________
MediaWiki announcements mailing list
To unsubscribe, go to:
https://lists.wikimedia.org/mailman/listinfo/mediawiki-announce
&lt;/pre&gt;</description>
    <dc:creator>Chris Steipp</dc:creator>
    <dc:date>2013-03-01T19:08:46</dc:date>
  </item>
  <item rdf:about="http://permalink.gmane.org/gmane.org.wikimedia.mediawiki.announce/190">
    <title>MediaWiki maintenance release 1.20.2</title>
    <link>http://permalink.gmane.org/gmane.org.wikimedia.mediawiki.announce/190</link>
    <description>&lt;pre&gt;I would like to announce the release of MediaWiki 1.20.2. This is a maintenance
release correcting issues from the 1.20.1 security release.

* (bug 42638) Fixes action=options&amp;amp;reset=1 in the API, and fixes unit tests.
* (bug 42370) Fixes backport of 60cc060 to use mDoneWrites instead of
   mTrxDoneWrites.

Full release notes:
&amp;lt;https://www.mediawiki.org/wiki/Release_notes/1.20&amp;gt;


**********************************************************************
Download:
&amp;lt;http://download.wikimedia.org/mediawiki/1.20/mediawiki-1.20.2.tar.gz&amp;gt;

Patch to previous version (1.20.1):
&amp;lt;http://download.wikimedia.org/mediawiki/1.20/mediawiki-1.20.2.patch.gz&amp;gt;

GPG signatures:
&amp;lt;http://download.wikimedia.org/mediawiki/1.20/mediawiki-1.20.2.tar.gz.sig&amp;gt;
&amp;lt;http://download.wikimedia.org/mediawiki/1.20/mediawiki-1.20.2.patch.gz.sig&amp;gt;

Public keys:
&amp;lt;https://secure.wikimedia.org/keys.html&amp;gt;

_______________________________________________
MediaWiki announcements mailing list
To unsubscribe, go to:
https://lists.wikimedia.org/mailman/listinfo/m&lt;/pre&gt;</description>
    <dc:creator>Chris Steipp</dc:creator>
    <dc:date>2012-12-04T23:20:45</dc:date>
  </item>
  <item rdf:about="http://permalink.gmane.org/gmane.org.wikimedia.mediawiki.announce/189">
    <title>MediaWiki security release: 1.20.1,1.19.3 and 1.18.6</title>
    <link>http://permalink.gmane.org/gmane.org.wikimedia.mediawiki.announce/189</link>
    <description>&lt;pre&gt;I would like to announce the release of MediaWiki 1.20.1, 1.19.3 and
1.18.6. These releases fix 3 security related bugs that could affect
users of MediaWiki. Download links are given at the end of this email
. Please note that support for the MediaWiki 1.18  branch ends this
month.

* During an internal review, it was discovered that MediaWiki core is
vulnerable to session fixation attacks. Successful exploitation could
allow an attacker to compromise another user's account. This issues
has been assigned CVE-2012-5391.  A similar vulnerability was also
identified in the CentralAuth Extension, and assigned CVE-2012-5395.
&amp;lt;https://bugzilla.wikimedia.org/show_bug.cgi?id=40995&amp;gt;
&amp;lt;https://bugzilla.wikimedia.org/show_bug.cgi?id=40962&amp;gt;

* Wikipedia user PleaseStand discovered that a new API feature in
MediaWiki 1.20 allowed for HTML code to be injected into the
"editfont" option. Since this option only affects the current user,
exploitation for XSS is difficult. However, users of MediaWiki 1.20
are encouraged to upg&lt;/pre&gt;</description>
    <dc:creator>Chris Steipp</dc:creator>
    <dc:date>2012-11-30T01:30:16</dc:date>
  </item>
  <item rdf:about="http://permalink.gmane.org/gmane.org.wikimedia.mediawiki.announce/188">
    <title>Pre-Release Announcement for MediaWiki 1.18.6,1.19.3, and 1.20.1</title>
    <link>http://permalink.gmane.org/gmane.org.wikimedia.mediawiki.announce/188</link>
    <description>&lt;pre&gt;On Thursday, November 29th, between 21:00-22:00 UTC (1-2pm PST)
Wikimedia Foundation will release security updates for current and
supported branches of the MediaWiki software. We are providing this
pre-announcement as a courtesy for administrators to be ready to
accept the fix for these on Thursday. We will send another
announcement email when the patches and tar files are ready for
download.

* Vulnerabilities were found in both MediaWiki core and the
CentralAuth extension. Successful exploitation could allow an attacker
to compromise another user's account. Risk is considered moderate
(CVSS Base Score: 4).
* One vulnerability was discovered that could allow an attacker to
prevent users from viewing Special:RecentChanges, and other pages,
which could prevent the detection of SPAM or vandalism. Public wikis
are encouraged to upgrade.
* A flaw in the MediaWiki 1.20 API could allow a stored XSS.
Exploitation requires user interaction or an existing XSS
vulnerability, so risk of exploitation is low.

For infor&lt;/pre&gt;</description>
    <dc:creator>Chris Steipp</dc:creator>
    <dc:date>2012-11-28T04:29:24</dc:date>
  </item>
  <item rdf:about="http://permalink.gmane.org/gmane.org.wikimedia.mediawiki.announce/187">
    <title>MediaWiki 1.20.0 released</title>
    <link>http://permalink.gmane.org/gmane.org.wikimedia.mediawiki.announce/187</link>
    <description>&lt;pre&gt;-----BEGIN PGP SIGNED MESSAGE-----
Hash: SHA1


I'm happy to announce the availability of the first stable release
of the new MediaWiki 1.20 release series.

MediaWiki 1.20 is a large release that contains many new features and
bug fixes. This is a summary of the major changes of interest to users.
You can consult the RELEASE-NOTES-1.20 file for the full list of changes
in this version.

Our thanks go to everyone who helped to improve MediaWiki by testing
the beta release and submitting bug reports.

== What's new? ==

MediaWiki 1.20 brings the usual host of various bugfixes and new features.

* Minimum PHP version is now 5.3.2.

* New diff view, greatly improved in clarity especially for
whitespace and other small changes and color-blind users.

* New special page Special:MostInterwikis.

* New magic word {{PAGEID}} which gives the current page ID.

* The info action has been reimplemented.

Internationalization:

* New languages supported: Emilian (egl), Tornedalen Finnish (fit),
Mizo (lus), Santali (sat),&lt;/pre&gt;</description>
    <dc:creator>Mark A. Hershberger</dc:creator>
    <dc:date>2012-11-07T01:22:40</dc:date>
  </item>
  <item rdf:about="http://permalink.gmane.org/gmane.org.wikimedia.mediawiki.announce/186">
    <title>MediaWiki security release: 1.19.2 and 1.18.5</title>
    <link>http://permalink.gmane.org/gmane.org.wikimedia.mediawiki.announce/186</link>
    <description>&lt;pre&gt;I would like to announce the release of MediaWiki 1.19.2 and 1.18.5.
These releases fix 6 security related bugs that could affect users of
MediaWiki. Download links are given at the end of this email.

* Wikipedia administrator Writ Keeper discovered a stored XSS (HTML
injection) vulnerability. This was possible due to the handling of
link text on File: links for nonexistent files. MediaWiki 1.16 and
later is affected. For more details, see
&amp;lt;https://bugzilla.wikimedia.org/show_bug.cgi?id=39700&amp;gt;

* User Fomafix reported several DOM-based XSS vulnerabilities, made
possible by a combination of loose filtering of the uselang parameter,
and JavaScript gadgets on various language Wikipedias. For more
details, see &amp;lt;https://bugzilla.wikimedia.org/show_bug.cgi?id=37587&amp;gt;

* During internal review, it was discovered that CSRF tokens,
available via the api, were not protected with X-Frame-Options
headers. This could lead to a CSRF vulnerability if the API response
is embedded in an external website using an iframe. For &lt;/pre&gt;</description>
    <dc:creator>Chris Steipp</dc:creator>
    <dc:date>2012-08-31T04:26:30</dc:date>
  </item>
  <item rdf:about="http://permalink.gmane.org/gmane.org.wikimedia.mediawiki.announce/185">
    <title>MediaWiki security release 1.19.1</title>
    <link>http://permalink.gmane.org/gmane.org.wikimedia.mediawiki.announce/185</link>
    <description>&lt;pre&gt;I would like to announce the release of MediaWiki 1.19.1. One security issue
was discovered.

Both Chris Steipp and Formafix discovered that the uselang http parameter
was vulnerable to XSS.

For more details, see https://bugzilla.wikimedia.org/show_bug.cgi?id=36938

Chris Steipp also improved the blacklisting of bad elements in SVG files.
This includes catching known
hostile files, and also disallowing the upload of svg files that include
remote resources.

This is work is part of an on-going effort to prevent exploits being hidden
in uploaded SVG files.

MediaWiki 1.19.1 also received a couple of other non-security bugfixes.

Full release notes:
https://gerrit.wikimedia.org/r/gitweb?p=mediawiki/core.git;a=blob_plain;f=RE
LEASE-NOTES-1.19;hb=1.19.1

https://www.mediawiki.org/wiki/Release_notes/1.19

**********************************************************************
Download:
http://download.wikimedia.org/mediawiki/1.19/mediawiki-1.19.1.tar.gz

Patch to previous version (1.19.0):
http://download.wikimedi&lt;/pre&gt;</description>
    <dc:creator>Sam Reed</dc:creator>
    <dc:date>2012-06-13T21:19:53</dc:date>
  </item>
  <item rdf:about="http://permalink.gmane.org/gmane.org.wikimedia.mediawiki.announce/184">
    <title>MediaWiki security release 1.18.4</title>
    <link>http://permalink.gmane.org/gmane.org.wikimedia.mediawiki.announce/184</link>
    <description>&lt;pre&gt;I would like to announce the release of MediaWiki 1.18.4. One security issue
was discovered.

Both Chris Steipp and Formafix discovered that the uselang http parameter
was vulnerable to XSS.

For more details, see https://bugzilla.wikimedia.org/show_bug.cgi?id=36938

Chris Steipp also improved the blacklisting of bad elements in SVG files.
This includes catching known
hostile files, and also disallowing the upload of svg files that include
remote resources.

This is work is part of an on-going effort to prevent exploits being hidden
in uploaded SVG files.

Full release notes:
https://gerrit.wikimedia.org/r/gitweb?p=mediawiki/core.git;a=blob_plain;f=RE
LEASE-NOTES-1.18;hb=1.18.4

https://www.mediawiki.org/wiki/Release_notes/1.18

**********************************************************************
Download:
http://download.wikimedia.org/mediawiki/1.18/mediawiki-1.18.4.tar.gz

Patch to previous version (1.18.3):
http://download.wikimedia.org/mediawiki/1.18/mediawiki-1.18.4.patch.gz

GPG signatures:
http://do&lt;/pre&gt;</description>
    <dc:creator>Sam Reed</dc:creator>
    <dc:date>2012-06-13T21:19:51</dc:date>
  </item>
  <item rdf:about="http://permalink.gmane.org/gmane.org.wikimedia.mediawiki.announce/183">
    <title>MediaWiki security release 1.17.5</title>
    <link>http://permalink.gmane.org/gmane.org.wikimedia.mediawiki.announce/183</link>
    <description>&lt;pre&gt;I would like to announce the release of MediaWiki 1.17.5. One security issue
was discovered.

Both Chris Steipp and Formafix discovered that the uselang http parameter
was vulnerable to XSS.

For more details, see https://bugzilla.wikimedia.org/show_bug.cgi?id=36938

Chris Steipp also improved the blacklisting of bad elements in SVG files.
This includes catching known
hostile files, and also disallowing the upload of svg files that include
remote resources.

This is work is part of an on-going effort to prevent exploits being hidden
in uploaded SVG files.

Full release notes:
https://gerrit.wikimedia.org/r/gitweb?p=mediawiki/core.git;a=blob_plain;f=RE
LEASE-NOTES;hb=1.17.5

https://www.mediawiki.org/wiki/Release_notes/1.17

**********************************************************************
Download:
http://download.wikimedia.org/mediawiki/1.17/mediawiki-1.17.5.tar.gz

Patch to previous version (1.17.4):
http://download.wikimedia.org/mediawiki/1.17/mediawiki-1.17.5.patch.gz

GPG signatures:
http://downloa&lt;/pre&gt;</description>
    <dc:creator>Sam Reed</dc:creator>
    <dc:date>2012-06-13T21:19:47</dc:date>
  </item>
  <item rdf:about="http://permalink.gmane.org/gmane.org.wikimedia.mediawiki.announce/182">
    <title>MediaWiki 1.19.0 released</title>
    <link>http://permalink.gmane.org/gmane.org.wikimedia.mediawiki.announce/182</link>
    <description>&lt;pre&gt;I'm happy to announce the availability of the first stable release
of the new MediaWiki 1.19 release series.

MediaWiki 1.19 is a large release that contains many new features and bug
fixes. This is a summary of the major changes of interest to users.
You can consult the RELEASE-NOTES-1.19 file for the full list of changes in
this version.

Our thanks go to everyone who helped to improve MediaWiki by testing the
beta
release and submitting bug reports.

****************************************************************
                             What's new?
****************************************************************

MediaWiki 1.19 brings the usual host of various bugfixes and new features.

Comprehensive list of what's new is in the release notes.

* Bumped MySQL version requirement to 5.0.2.
* Disable the partial HTML and MathML rendering options for Math,
  and render as PNG by  default.
  * MathML mode was so incomplete most people thought it simply didn't work.
* New skins/common/*.css files usable&lt;/pre&gt;</description>
    <dc:creator>Sam Reed</dc:creator>
    <dc:date>2012-05-02T14:31:31</dc:date>
  </item>
  <item rdf:about="http://permalink.gmane.org/gmane.org.wikimedia.mediawiki.announce/181">
    <title>MediaWiki 1.19.0rc1</title>
    <link>http://permalink.gmane.org/gmane.org.wikimedia.mediawiki.announce/181</link>
    <description>&lt;pre&gt;I'm happy to announce the availability of the first release candidate
release of the new MediaWiki 1.19 release series.

Please test it and let us know what you think of it. Barring new bug
reports, this release candidate will soon be released as MediaWiki 1.19.0.

Please try it out and let us know what you think. Don't run it on any
wikis that you really care about, unless you are both very brave and
very confident in your MediaWiki administration skills.

MediaWiki 1.19 is a large release that contains many new features and
bug fixes. This is a summary of the major changes of interest to users.
You can consult the RELEASE-NOTES-1.19 file for the full list of changes
in this version.

Our thanks go to everyone who helped to improve MediaWiki by testing
the beta release and submitting bug reports.

****************************************************************
                             What's new?
****************************************************************

MediaWiki 1.19 brings the usual host of v&lt;/pre&gt;</description>
    <dc:creator>Sam Reed</dc:creator>
    <dc:date>2012-04-26T15:25:48</dc:date>
  </item>
  <item rdf:about="http://permalink.gmane.org/gmane.org.wikimedia.mediawiki.announce/180">
    <title>MediaWiki maintenance release 1.18.3</title>
    <link>http://permalink.gmane.org/gmane.org.wikimedia.mediawiki.announce/180</link>
    <description>&lt;pre&gt;I would like to announce the release of MediaWiki 1.18.3. This release
correct issues

from the 1.18.2 security release, and also some other bugs.

 

* (bug 35446) Using "{{nse:}}" with an invalid namespace name no longer
throws

  a PHP warning.

* (bug 35567) The whole password reminder e-mail is now sent in the same
language.

* (bug 35961) Hash comparison should always be strict.

* (bug 35671) PHP Notice: Undefined index: gettoken in
includes/api/ApiMain.php

  on line 598.

* Fix broken email confirmation expiration caused by MWCryptRand changes.

 

Full release notes:

https://gerrit.wikimedia.org/r/gitweb?p=mediawiki/core.git;a=blob;f=RELEASE-
NOTES-1.18;hb=REL1_18

https://www.mediawiki.org/wiki/Release_notes/1.18

 

 

**********************************************************************

Download:

http://download.wikimedia.org/mediawiki/1.18/mediawiki-1.18.3.tar.gz

 

Patch to previous version (1.18.2):

http://download.wikimedia.org/mediawiki/1.18/mediawiki-1.18.3.patch.gz

 

GPG signature&lt;/pre&gt;</description>
    <dc:creator>Sam Reed</dc:creator>
    <dc:date>2012-04-26T15:25:43</dc:date>
  </item>
  <item rdf:about="http://permalink.gmane.org/gmane.org.wikimedia.mediawiki.announce/179">
    <title>MediaWiki maintenance release 1.17.4</title>
    <link>http://permalink.gmane.org/gmane.org.wikimedia.mediawiki.announce/179</link>
    <description>&lt;pre&gt;I would like to announce the release of MediaWiki 1.17.4. This release
correct issues
from the 1.17.3 security release, and also some other bugs.

* (bug 35961) Hash comparison should always be strict.
* Fix broken email confirmation expiration caused by MWCryptRand changes.
* (bug 35671) PHP Notice: Undefined index: gettoken in
includes/api/ApiMain.php
  on line 598.

Full release notes:
https://gerrit.wikimedia.org/r/gitweb?p=mediawiki/core.git;a=blob;f=RELEASE-
NOTES;hb=REL1_17
https://www.mediawiki.org/wiki/Release_notes/1.17


**********************************************************************
Download:
http://download.wikimedia.org/mediawiki/1.17/mediawiki-1.17.4.tar.gz

Patch to previous version (1.17.3):
http://download.wikimedia.org/mediawiki/1.17/mediawiki-1.17.4.patch.gz

GPG signatures:
http://download.wikimedia.org/mediawiki/1.17/mediawiki-1.17.4.tar.gz.sig
http://download.wikimedia.org/mediawiki/1.17/mediawiki-1.17.4.patch.gz.sig

Public keys:
https://secure.wikimedia.org/keys.html


_______&lt;/pre&gt;</description>
    <dc:creator>Sam Reed</dc:creator>
    <dc:date>2012-04-26T15:25:39</dc:date>
  </item>
  <item rdf:about="http://permalink.gmane.org/gmane.org.wikimedia.mediawiki.announce/178">
    <title>MediaWiki 1.19.0beta2</title>
    <link>http://permalink.gmane.org/gmane.org.wikimedia.mediawiki.announce/178</link>
    <description>&lt;pre&gt;I'm happy to announce the availability of the second beta release of the
new MediaWiki 1.19 release series.

Please try it out and let us know what you think. Don't run it on any
wikis that you really care about, unless you are both very brave and
very confident in your MediaWiki administration skills.

MediaWiki 1.19 is a large release that contains many new features and
bug fixes. This is a summary of the major changes of interest to users.
You can consult the RELEASE-NOTES-1.19 file for the full list of changes
in this version.

Five security issues were discovered.

It was discovered that the api had a cross-site request forgery (CSRF)
vulnerability in the block/unblock modules. It was possible for a user
account with the block privileges to block or unblock another user without
providing a token.

For more details, see https://bugzilla.wikimedia.org/show_bug.cgi?id=34212

It was discovered that the resource loader can leak certain kinds of private
data across domain origin boundaries, by providing the d&lt;/pre&gt;</description>
    <dc:creator>Sam Reed</dc:creator>
    <dc:date>2012-03-22T19:37:34</dc:date>
  </item>
  <item rdf:about="http://permalink.gmane.org/gmane.org.wikimedia.mediawiki.announce/177">
    <title>MediaWiki security and maintenance release1.17.3</title>
    <link>http://permalink.gmane.org/gmane.org.wikimedia.mediawiki.announce/177</link>
    <description>&lt;pre&gt;I would like to announce the release of MediaWiki 1.17.3. Five security
issues were discovered.

It was discovered that the api had a cross-site request forgery (CSRF)
vulnerability in the block/unblock modules. It was possible for a user
account with the block privileges to block or unblock another user without
providing a token.

For more details, see https://bugzilla.wikimedia.org/show_bug.cgi?id=34212

It was discovered that the resource loader can leak certain kinds of private
data across domain origin boundaries, by providing the data as an executable
JavaScript file. In MediaWiki 1.18 and later, this includes the leaking of
CSRF
protection tokens. This allows compromise of the wiki's user accounts, say
by
changing the user's email address and then requesting a password reset.

For more details, see https://bugzilla.wikimedia.org/show_bug.cgi?id=34907

Jan Schejbal of Hatforce.com discovered a cross-site request forgery (CSRF)
vulnerability in Special:Upload. Modern browsers (since at least as early as&lt;/pre&gt;</description>
    <dc:creator>Sam Reed</dc:creator>
    <dc:date>2012-03-22T19:37:29</dc:date>
  </item>
  <item rdf:about="http://permalink.gmane.org/gmane.org.wikimedia.mediawiki.announce/176">
    <title>MediaWiki security and maintenance release1.18.2</title>
    <link>http://permalink.gmane.org/gmane.org.wikimedia.mediawiki.announce/176</link>
    <description>&lt;pre&gt;I would like to announce the release of MediaWiki 1.18.2. Five security
issues were discovered.

It was discovered that the api had a cross-site request forgery (CSRF)
vulnerability in the block/unblock modules. It was possible for a user
account with the block privileges to block or unblock another user without
providing a token.

For more details, see https://bugzilla.wikimedia.org/show_bug.cgi?id=34212

It was discovered that the resource loader can leak certain kinds of private
data across domain origin boundaries, by providing the data as an executable
JavaScript file. In MediaWiki 1.18 and later, this includes the leaking of
CSRF
protection tokens. This allows compromise of the wiki's user accounts, say
by
changing the user's email address and then requesting a password reset.

For more details, see https://bugzilla.wikimedia.org/show_bug.cgi?id=34907

Jan Schejbal of Hatforce.com discovered a cross-site request forgery (CSRF)
vulnerability in Special:Upload. Modern browsers (since at least as early as&lt;/pre&gt;</description>
    <dc:creator>Sam Reed</dc:creator>
    <dc:date>2012-03-22T19:37:32</dc:date>
  </item>
  <textinput rdf:about="http://search.gmane.org/?group=$group=gmane.org.wikimedia.mediawiki.announce">
    <title>Search Engine</title>
    <description>Search the mailing list at Gmane</description>
    <name>query</name>
    <link>http://search.gmane.org/?group=$group=gmane.org.wikimedia.mediawiki.announce</link>
  </textinput>
</rdf:RDF>
