Posted
7 days
ago
by
Tim Starling
-----BEGIN PGP SIGNED MESSAGE-----
Hash: SHA1
MediaWiki 1.13.0 is now available.
MediaWiki is now using a "continuous integration" development model
with quarterly snapshot releases. The latest development code is
always
... [More]
kept "ready to run", and in fact runs our own sites on
Wikipedia. MediaWiki 1.13.0 is our latest snapshot release, based on
the development code from three weeks ago, with several bugfixes applied.
Selected changes since MediaWiki 1.12.0:
* 59,000 new localised text messages have been added, taking the total
to 266,000, spread across 281 languages
* New special pages: FileDuplicateSearch, ListGroupRights
* Special:UserRights and Special:SpecialPages have been redesigned
* More options on Special:Recentchangeslinked and Special:WhatLinksHere
* New parser functions: PAGESINCATEGORY, PAGESIZE
* Can hide categories with __HIDDENCAT__
* Friendlier behaviour for users who click a red link but can't edit
* Image redirects are now enabled by default
* Drop-down AJAX search suggestions ($wgEnableMWSuggest)
* Search results show image thumbnails
* The search box in the MonoBook sidebar can be moved up by editing
[[MediaWiki:Sidebar]]
* Double redirects created by a page move can be fixed automatically
Changes since release candidate MediaWiki 1.13.0rc2:
* (bug 13770) Fixed incorrect detection of PHP's DOM module
* Fix regression from r37834: accesskey tooltip hint should be given
for the
minor edit and watch labels on the edit page.
* Updated Chinese simplified/traditional conversion tables
Full release notes:
http://svn.wikimedia.org/svnroot/mediawiki/tags/REL1_13_0/phase3/RELEASE-NOTES
**********************************************************************
Download:
http://download.wikimedia.org/mediawiki/1.13/mediawiki-1.13.0.tar.gz
Patch to previous version (1.13.0rc2)
http://download.wikimedia.org/mediawiki/1.13/mediawiki-1.13.0.patch.gz
GPG signatures:
http://download.wikimedia.org/mediawiki/1.13/mediawiki-1.13.0.tar.gz.sig
http://download.wikimedia.org/mediawiki/1.13/mediawiki-1.13.0.patch.gz.sig
Public keys:
https://secure.wikimedia.org/keys.html
SHA-1 checksums:
f53f7548510a39fd9f365d3097e8a581fdb14353 mediawiki-1.13.0.tar.gz
7243a2b50edb78b6f1882ff09c0882e771502539 mediawiki-1.13.0.patch.gz
MD5 checksums:
6e51cb81fd57d90b870e984688734db6 mediawiki-1.13.0.tar.gz
a4880023b196238cb0a77af717b4fd8b mediawiki-1.13.0.patch.gz
- --
Tim Starling
-----BEGIN PGP SIGNATURE-----
Version: GnuPG v1.4.6 (GNU/Linux)
Comment: Using GnuPG with Mozilla - http://enigmail.mozdev.org
iD8DBQFIpE7CdWgrCOij/sQRAthwAKC9agD3P0CMjXeWTaaHGsmfXvWEfgCfYxSo
nKl2tvJq BT8u16CjPrG3tI=
=Jk7Q
-----END PGP SIGNATURE----- [Less]
Posted
11 days
ago
by
Tim Starling
-----BEGIN PGP SIGNED MESSAGE-----
Hash: SHA1
A second release candidate for MediaWiki 1.13 is now available. Please
try it
out and tell us if it works for you. This is a beta release and should
be used with
... [More]
care.
Selected changes since MediaWiki 1.13.0rc1:
* Removed $wgForwardSearchUrl
* Added magic word __STATICREDIRECT__ to suppress the redirect fixer
* Fixed bugs 14907, 14966, 14987, 13376, 14904, 15035 and 14944.
Selected changes since MediaWiki 1.12.0:
* New special pages: FileDuplicateSearch, ListGroupRights
* Special:UserRights and Special:SpecialPages have been redesigned
* More options on Special:Recentchangeslinked and Special:WhatLinksHere
* New parser functions: PAGESINCATEGORY, PAGESIZE
* Can hide categories with __HIDDENCAT__
* Friendlier behaviour for users who click a red link but can't edit
* Image redirects are now enabled by default
* Drop-down AJAX search suggestions ($wgEnableMWSuggest)
* Search results show image thumbnails
* The search box in the MonoBook sidebar can be moved up by editing
[[MediaWiki:Sidebar]]
* Double redirects created by a page move can be fixed automatically
Full release notes:
http://svn.wikimedia.org/svnroot/mediawiki/tags/REL1_13_0RC2/phase3/RELEASE-NOTES
Download:
http://download.wikimedia.org/mediawiki/1.13/mediawiki-1.13.0rc2.tar.gz
GPG signatures:
http://download.wikimedia.org/mediawiki/1.13/mediawiki-1.13.0rc2.tar.gz.sig
Public keys:
https://secure.wikimedia.org/keys.html
SHA-1 checksums:
20fa379f70f85b3f2bd72cb1d7eb06dd4cbd2846 mediawiki-1.13.0rc2.tar.gz
MD-5 checksums:
82c24570ace0a90c4192b9225b3b019f mediawiki-1.13.0rc2.tar.gz
- --
Tim Starling
-----BEGIN PGP SIGNATURE-----
Version: GnuPG v1.4.6 (GNU/Linux)
Comment: Using GnuPG with Mozilla - http://enigmail.mozdev.org
iD8DBQFIn8aDdWgrCOij/sQRAueAAJsEO UrhY7W7 wjM/TN125R3pUp0QCfUon2
jUoK8hqfZ0sIXtf/4G9cA2Q=
=roc2
-----END PGP SIGNATURE----- [Less]
Posted
28 days
ago
by
Tim Starling
-----BEGIN PGP SIGNED MESSAGE-----
Hash: SHA1
A release candidate for MediaWiki 1.13 is now available. Please try it
out and tell us if it works for you. This is a beta release and is not
recommended for use in a production
... [More]
environment (except if you're
really clever like us).
Selected changes since MediaWiki 1.12.0:
* New special pages: FileDuplicateSearch, ListGroupRights
* Special:UserRights and Special:SpecialPages have been redesigned
* More options on Special:Recentchangeslinked and Special:WhatLinksHere
* New parser functions: PAGESINCATEGORY, PAGESIZE
* Can hide categories with __HIDDENCAT__
* Friendlier behaviour for users who click a red link but can't edit
* Image redirects are now enabled by default
* Drop-down AJAX search suggestions ($wgEnableMWSuggest)
* Search results show image thumbnails
* The search box in the MonoBook sidebar can be moved up by editing
[[MediaWiki:Sidebar]]
* Double redirects created by a page move can be fixed automatically
Full release notes:
http://svn.wikimedia.org/svnroot/mediawiki/tags/REL1_13_0RC1/phase3/RELEASE-NOTES
Download:
http://download.wikimedia.org/mediawiki/1.13/mediawiki-1.13.0rc1.tar.gz
GPG signatures:
http://download.wikimedia.org/mediawiki/1.13/mediawiki-1.13.0rc1.tar.gz.sig
Public keys:
https://secure.wikimedia.org/keys.html
SHA-1 checksums:
be9a2645ea38d074b05a726e5ac2f3699ab482f8 mediawiki-1.13.0rc1.tar.gz
MD-5 checksums:
042a8662d2fcce0e8c5a3a5c17ce6d59 mediawiki-1.13.0rc1.tar.gz
Before asking for help, try the FAQ:
http://www.mediawiki.org/wiki/Manual:FAQ
Low-traffic release announcements mailing list:
(Please subscribe to receive announcements of security updates.)
http://lists.wikimedia.org/mailman/listinfo/mediawiki-announce
Wiki admin help mailing list:
http://lists.wikimedia.org/mailman/listinfo/mediawiki-l
Bug report system:
http://bugzilla.wikimedia.org/
Play "stump the developers" live on IRC:
#mediawiki on irc.freenode.net
- -- Tim Starling
-----BEGIN PGP SIGNATURE-----
Version: GnuPG v1.4.6 (GNU/Linux)
Comment: Using GnuPG with Mozilla - http://enigmail.mozdev.org
iD8DBQFIiJuPdWgrCOij/sQRAgEYAJ4tm0QG6RLQN/zL/zglMZG/HqenIACgg9aD
qQdsAu v8xtclPuv2wl1ZMA=
=RqPl
-----END PGP SIGNATURE----- [Less]
Posted
2 months
ago
by
Tim Starling
The following extensions had cross-site scripting (XSS) vulnerabilities:
* geo
* MetavidWiki
* wikihiero
These vulnerabilities are exploitable even if the extensions are
disabled. If you have any of these extensions
... [More]
installed, please update
them immediately.
Many shared hosting services have the php.ini setting "register_globals"
enabled, despite the fact that it is known to be detrimental to security.
A new automated vulnerability scanner has found a large number of
security vulnerabilities in MediaWiki extensions, when register_globals
is enabled. Unless you are sure you have register_globals disabled, the
following extensions should be immediately updated:
Cross-site scripting vulnerabilities:
* Call
* ChangeAuthor
* EditOwn
* SignDocument
* TemplateLink
* WatchSubpages
* WhoIsWatching
* php/ext/MediaWiki
Arbitrary script inclusion vulnerabilities:
* CategoryIntersection
* Makebot
* PasswordReset
* regexBlock
* SemanticCalendar
* SemanticForms
* SemanticMediaWiki
* SocialProfile
* SpamRegex
* StalePages
* TodoTasks
* WhiteList
* Wikidata
All these extensions are vulnerable regardless of whether they are
enabled in LocalSettings.php. They only need to be installed, with their
installation directory accessible from the public internet.
Downloads in .tar.gz form for all these MediaWiki extensions are
available from:
http://www.mediawiki.org/wiki/Special:ExtensionDistributor
Or using a subversion client from:
http://svn.wikimedia.org/svnroot/mediawiki/trunk/extensions [Less]
Posted
5 months
ago
by
Brion Vibber
-----BEGIN PGP SIGNED MESSAGE-----
Hash: SHA1
No problems reported with 1.12.0rc1, so here's the final release. Enjoy!
Full release
... [More]
notes:
http://svn.wikimedia.org/svnroot/mediawiki/tags/REL1_12_0/phase3/RELEASE-NOTES
Download:
http://download.wikimedia.org/mediawiki/1.12/mediawiki-1.12.0.tar.gz
GPG signature:
http://download.wikimedia.org/mediawiki/1.12/mediawiki-1.12.0.tar.gz.sig
SHA-1 checksum:
48bf1877f60c317cbe93c072187dfe9c1aa3b857 mediawiki-1.12.0.tar.gz
MD-5 checksum:
MD5 (mediawiki-1.12.0.tar.gz) = 117a1360f440883a51f0ebca32906ea0
Before asking for help, try the FAQ:
http://www.mediawiki.org/wiki/Manual:FAQ
Low-traffic release announcements mailing list:
(Please subscribe to receive announcements of security updates.)
http://lists.wikimedia.org/mailman/listinfo/mediawiki-announce
Wiki admin help mailing list:
http://lists.wikimedia.org/mailman/listinfo/mediawiki-l
Bug report system:
http://bugzilla.wikimedia.org/
Play "stump the developers" live on IRC:
#mediawiki on irc.freenode.net
- -- brion vibber (brion < at > wikimedia.org)
-----BEGIN PGP SIGNATURE-----
Version: GnuPG v1.4.8 (Darwin)
Comment: Using GnuPG with Mozilla - http://enigmail.mozdev.org
iEYEARECAAYFAkfi4fcACgkQwRnhpk1wk46HEACaAvMj2oHe0stHrXdhKWUR2fF8
CosAoKvS5oWuitWIgT7rTh N06kNNmqt
=j1cY
-----END PGP SIGNATURE----- [Less]