Next | Query returned 2 messages, browsing 1 to 10 | previous

History of commit frequency

CVS Commit History:


   2009-02-23 15:11:52 by Matthias Scheler | Files touched by this commit (2) | Package updated
Log message:
Pullup ticket #2707 - requested by martti
mediawiki: bug fix update

Revisions pulled up:
- www/mediawiki/Makefile			1.5
- www/mediawiki/distinfo			1.4
---
Module Name:	pkgsrc
Committed By:	martti
Date:		Sun Feb 22 11:58:57 UTC 2009

Modified Files:
	pkgsrc/www/mediawiki: Makefile distinfo

Log message:
Updated www/mediawiki to 1.13.5

This is a maintenance release which corrects some bugs in the installer,
introduced during the hasty security release of 1.13.4. It is not
necessary to upgrade if you do not intend on using the installer.
   2009-02-07 20:56:33 by Matthias Scheler | Files touched by this commit (3) | Package updated
Log message:
Pullup ticket #2690 - requested by martti
mediawiki: security update

Revisions pulled up:
- www/mediawiki/Makefile			1.4
- www/mediawiki/PLIST				1.3
- www/mediawiki/distinfo			1.3
---
Module Name:	pkgsrc
Committed By:	martti
Date:		Sat Feb  7 11:09:37 UTC 2009

Modified Files:
	pkgsrc/www/mediawiki: Makefile PLIST distinfo

Log message:
Updated www/mediawiki to 1.13.4

A number of cross-site scripting (XSS) security vulnerabilities were
discovered in the web-based installer (config/index.php). These
vulnerabilities all require a live installer -- once the installer has been
used to install a wiki, it is deactivated.

Note that cross-site scripting vulnerabilities can be used to attack any
website in the same cookie domain. So if you have an uninstalled copy of
MediaWiki on the same site as an active web service, MediaWiki could be used
to attack the active service.  If you are hosting an old copy of MediaWiki
that you have never installed, we advise you to remove it from the web.

Next | Query returned 2 messages, browsing 1 to 10 | previous