diff options
author | Pierre Schmitz <pierre@archlinux.de> | 2011-04-13 05:42:02 +0200 |
---|---|---|
committer | Pierre Schmitz <pierre@archlinux.de> | 2011-04-13 05:42:02 +0200 |
commit | 124299758ca7454561118f466a0470905758924f (patch) | |
tree | f4d09ea1286d6747ae36aecd4ba28dfb04c9e7c5 /RELEASE-NOTES | |
parent | 3bddedf685051638fdba61268ad195fee041db1c (diff) |
update to MediaWiki 1.16.3
Diffstat (limited to 'RELEASE-NOTES')
-rw-r--r-- | RELEASE-NOTES | 15 |
1 files changed, 13 insertions, 2 deletions
diff --git a/RELEASE-NOTES b/RELEASE-NOTES index 71534ca4..cf3f3a77 100644 --- a/RELEASE-NOTES +++ b/RELEASE-NOTES @@ -1,8 +1,8 @@ = MediaWiki release notes = -== MediaWiki 1.16.2 == +== MediaWiki 1.16.3 == -2011-02-01 +2011-04-12 This is a security and maintenance release of the MediaWiki 1.16 branch. @@ -44,6 +44,17 @@ set $wgCacheDirectory to a writable path on the local filesystem. Make sure you have the DBA extension for PHP installed, this will improve performance further. +== Changes since 1.16.2 == + +* (bug 28449) Fixed permissions checks in Special:Import which allowed users + without the 'import' permission to import pages from the configured import + sources. +* (bug 28235) Fixed XSS affecting IE 6 and earlier clients only, due to those + browsers looking for a file extension in the query string of the URL, and + ignoring the Content-Type header if one is found. +* (bug 28450) Fixed a CSS validation issue involving escaped comments, which + led to XSS for Internet Explorer clients and privacy loss for other clients. + == Changes since 1.16.1 == * (bug 26642) Fixed incorrect translated namespace due to a regression in the |