mediawiki (1:1.19.20+dfsg-2.3) unstable; urgency=high * Non-maintainer upload. * Add patch fixing several security issues: - (bug T85848, bug T71210) SECURITY: Don't parse XMP blocks that contain XML entities, to prevent various DoS attacks. - (bug T88310) SECURITY: Always expand xml entities when checking SVG's. - (bug T73394) SECURITY: Escape > in Html::expandAttributes to prevent XSS. - (bug T85855) SECURITY: Don't execute another user's CSS or JS on preview. - (bug T85349, bug T85850, bug T86711) SECURITY: Multiple issues fixed in SVG filtering to prevent XSS and protect viewer's privacy. -- Thijs Kinkhorst Mon, 06 Apr 2015 16:53:54 +0000 mediawiki (1:1.19.20+dfsg-2.2) unstable; urgency=medium * Non-maintainer upload. * Add patch fixing T76686: thumb.php outputs wikitext message as raw HTML, which could lead to xss. Permission to edit MediaWiki namespace is required to exploit this. -- Sebastien Delafond Sun, 21 Dec 2014 13:11:10 +0100 mediawiki (1:1.19.20+dfsg-2.1) unstable; urgency=medium * Non-maintainer upload. * CVE-2014-9277: The mangling in OutputHandler.php poses a potentially severe security problem for API clients written in PHP, in that format=php is affected (Closes: #772764). -- Sebastien Delafond Sun, 14 Dec 2014 18:23:47 +0100 mediawiki (1:1.19.20+dfsg-2) unstable; urgency=low * Team upload. * Remove myself from Uploaders. -- Thorsten Glaser Tue, 07 Oct 2014 18:13:52 +0000 mediawiki (1:1.19.20+dfsg-1) unstable; urgency=medium * Make debian/rules get-orig-source-tg call uscan automatically * New upstream security release: - (bug 70672) SECURITY: OutputPage: Remove separation of css and js module allowance. -- Thorsten Glaser Thu, 02 Oct 2014 10:50:16 +0200 mediawiki (1:1.19.19+dfsg-1) unstable; urgency=medium [ Mert Dirik ] * Update turkish Debconf translation (Closes: #759878) [ Thorsten Glaser ] * Remove Romain Beauxis’ bouncing eMail address * Acknowledge NMU (1:1.19.18+dfsg-0.1) – thanks! * New upstream security and maintenance release: - (bug 69008) SECURITY: Enhance CSS filtering in SVG files. Filter