Sync mediawiki 1:1.15.5-1 (universe) from Debian unstable (main)

Bug #611069 reported by Jonathan Wiltshire
8
This bug affects 1 person
Affects Status Importance Assigned to Milestone
mediawiki (Ubuntu)
Fix Released
Wishlist
Unassigned

Bug Description

Binary package hint: mediawiki

Please sync the new upstream security release from sid to fix #610782 and #610819, plus a further bug that does not have a Launchpad report.

Here is the changelog since the current version:

mediawiki (1:1.15.5-1) unstable; urgency=high

  [ Thorsten Glaser ]
  * debian/patches/suppress_warnings.patch: new, suppress warnings
    about session_start() being called twice also in the PHP error
    log, not just MediaWiki’s, for example run from FusionForge

  [ Jonathan Wiltshire ]
  * New upstream security release:
    - correctly set caching headers to prevent private data leakage
         (closes: #590660, LP: #610782)
    - fix XSS vulnerability in profileinfo.php
         (closes: #590669, LP: #610819)

 -- Jonathan Wiltshire <email address hidden> Wed, 28 Jul 2010 12:23:04 +0100

Changed in mediawiki (Ubuntu):
importance: Undecided → Wishlist
Revision history for this message
StefanPotyra (sistpoty) wrote :

subscribing sponsors, unsubscribing release-team, as we're not yet in feature freeze.

Revision history for this message
Launchpad Janitor (janitor) wrote :

This bug was fixed in the package mediawiki - 1:1.15.5-1

---------------
mediawiki (1:1.15.5-1) unstable; urgency=high

  [ Thorsten Glaser ]
  * debian/patches/suppress_warnings.patch: new, suppress warnings
    about session_start() being called twice also in the PHP error
    log, not just MediaWiki’s, for example run from FusionForge

  [ Jonathan Wiltshire ]
  * New upstream security release:
    - correctly set caching headers to prevent private data leakage
         (closes: #590660, LP: #610782)
    - fix XSS vulnerability in profileinfo.php
         (closes: #590669, LP: #610819)
 -- Jonathan Wiltshire <email address hidden> Wed, 28 Jul 2010 12:23:04 +0100

Changed in mediawiki (Ubuntu):
status: New → Fix Released
To post a comment you must log in.
This report contains Public information  
Everyone can see this information.

Other bug subscribers

Remote bug watches

Bug watches keep track of this bug in other bug trackers.