diff options
author | Pierre Schmitz <pierre@archlinux.de> | 2007-02-05 10:49:51 +0000 |
---|---|---|
committer | Pierre Schmitz <pierre@archlinux.de> | 2007-02-05 10:49:51 +0000 |
commit | c39aeb62f7e8dfb6ba6467beb2d9d6f97fd84959 (patch) | |
tree | 187c3b0b29a4baf4a6e23b053abf8a94ee62e085 /RELEASE-NOTES | |
parent | 471fc27fc958b3495b92057c88eb4b8f75792f88 (diff) |
Aktualisierung auf MediaWiki 1.9.2
Diffstat (limited to 'RELEASE-NOTES')
-rw-r--r-- | RELEASE-NOTES | 19 |
1 files changed, 19 insertions, 0 deletions
diff --git a/RELEASE-NOTES b/RELEASE-NOTES index 6c1a8626..77ae6c5f 100644 --- a/RELEASE-NOTES +++ b/RELEASE-NOTES @@ -3,6 +3,25 @@ Security reminder: MediaWiki does not require PHP's register_globals setting since version 1.2.0. If you have it on, turn it *off* if you can. +== MediaWiki 1.9.2 == + +February 4, 2007 + +This is a bug-fix update that fixes some installation and other minor +issues with the 1.9.1 release as well as a security issue which was +introduced in the 1.9 branch. + +JavaScript code which regenerated the "sortable tables" feature did +not properly sanitize input, leading to an HTML injection vulnerability. + +* (bug 8774) Fix path for GNU FDL rights icon on new installs +* (bug 8819) Fix full path disclosure with skins dependencies +* (bug 4268) Fixed data-loss bug in compressOld batch text compression + affecting pages which had null edits (move, protect, etc) as second + edit in a batch group. Isolated and patched by Travis Derouin. +* Security fix for sortable tables JavaScript + + == MediaWiki 1.9.1 == January 24, 2007 |