From 4fe7385a8edd62dd7d36fedb157f296e5a57002a Mon Sep 17 00:00:00 2001 From: Pierre Schmitz Date: Mon, 9 Feb 2009 23:10:10 +0100 Subject: updated to 1.13.4 --- RELEASE-NOTES | 21 +- config/index.php | 77 +- includes/DefaultSettings.php | 4 +- includes/GlobalFunctions.php | 15 + includes/db/DatabasePostgres.php | 102 +- languages/Names.php | 4 + languages/messages/MessagesAf.php | 2 +- languages/messages/MessagesAm.php | 339 ++-- languages/messages/MessagesAn.php | 4 +- languages/messages/MessagesArz.php | 8 +- languages/messages/MessagesAvk.php | 4 +- languages/messages/MessagesBat_smg.php | 3 + languages/messages/MessagesBcc.php | 2 +- languages/messages/MessagesBcl.php | 20 +- languages/messages/MessagesBe.php | 11 +- languages/messages/MessagesBn.php | 123 +- languages/messages/MessagesBs.php | 8 +- languages/messages/MessagesCa.php | 4 +- languages/messages/MessagesCdo.php | 2 +- languages/messages/MessagesCs.php | 2 +- languages/messages/MessagesCsb.php | 2 +- languages/messages/MessagesCu.php | 8 + languages/messages/MessagesCy.php | 6 +- languages/messages/MessagesDa.php | 10 +- languages/messages/MessagesDe.php | 28 +- languages/messages/MessagesDe_formal.php | 20 +- languages/messages/MessagesDiq.php | 136 +- languages/messages/MessagesDsb.php | 26 +- languages/messages/MessagesDv.php | 82 +- languages/messages/MessagesEl.php | 21 +- languages/messages/MessagesEs.php | 37 +- languages/messages/MessagesEt.php | 379 ++-- languages/messages/MessagesEu.php | 65 +- languages/messages/MessagesFa.php | 4 +- languages/messages/MessagesFi.php | 6 +- languages/messages/MessagesFiu_vro.php | 29 +- languages/messages/MessagesFr.php | 51 +- languages/messages/MessagesGa.php | 42 +- languages/messages/MessagesGd.php | 2 +- languages/messages/MessagesGl.php | 10 +- languages/messages/MessagesGn.php | 116 +- languages/messages/MessagesGrc.php | 72 +- languages/messages/MessagesGsw.php | 410 +++-- languages/messages/MessagesGu.php | 22 +- languages/messages/MessagesHaw.php | 35 +- languages/messages/MessagesHe.php | 6 +- languages/messages/MessagesHif_latn.php | 57 +- languages/messages/MessagesHr.php | 6 +- languages/messages/MessagesHsb.php | 2 + languages/messages/MessagesHt.php | 8 +- languages/messages/MessagesHu.php | 43 +- languages/messages/MessagesIs.php | 56 +- languages/messages/MessagesIt.php | 2 +- languages/messages/MessagesJa.php | 182 +- languages/messages/MessagesKa.php | 11 +- languages/messages/MessagesKaa.php | 367 +++- languages/messages/MessagesKab.php | 2 +- languages/messages/MessagesKm.php | 180 +- languages/messages/MessagesKo.php | 322 +++- languages/messages/MessagesKsh.php | 64 +- languages/messages/MessagesKu_arab.php | 19 +- languages/messages/MessagesLa.php | 10 +- languages/messages/MessagesLb.php | 27 +- languages/messages/MessagesLi.php | 13 +- languages/messages/MessagesLt.php | 106 +- languages/messages/MessagesLv.php | 4 +- languages/messages/MessagesMdf.php | 7 +- languages/messages/MessagesMk.php | 30 +- languages/messages/MessagesMl.php | 17 +- languages/messages/MessagesMn.php | 67 +- languages/messages/MessagesMr.php | 2 +- languages/messages/MessagesMs.php | 2 +- languages/messages/MessagesMt.php | 10 +- languages/messages/MessagesMwl.php | 143 +- languages/messages/MessagesNah.php | 388 +++- languages/messages/MessagesNap.php | 12 + languages/messages/MessagesNds.php | 6 +- languages/messages/MessagesNds_nl.php | 12 +- languages/messages/MessagesNl.php | 4 +- languages/messages/MessagesNn.php | 26 +- languages/messages/MessagesOc.php | 2 +- languages/messages/MessagesOs.php | 30 +- languages/messages/MessagesPs.php | 113 +- languages/messages/MessagesPt_br.php | 173 +- languages/messages/MessagesQu.php | 5 +- languages/messages/MessagesRm.php | 496 +++++- languages/messages/MessagesRo.php | 129 +- languages/messages/MessagesRu.php | 4 +- languages/messages/MessagesSa.php | 64 +- languages/messages/MessagesScn.php | 3 + languages/messages/MessagesSe.php | 2 +- languages/messages/MessagesSk.php | 15 +- languages/messages/MessagesSma.php | 2 +- languages/messages/MessagesSo.php | 8 +- languages/messages/MessagesSq.php | 2 +- languages/messages/MessagesSr_ec.php | 35 +- languages/messages/MessagesSu.php | 69 +- languages/messages/MessagesSv.php | 4 +- languages/messages/MessagesSw.php | 16 +- languages/messages/MessagesSzl.php | 250 +-- languages/messages/MessagesTe.php | 13 +- languages/messages/MessagesTet.php | 8 +- languages/messages/MessagesTg_cyrl.php | 148 +- languages/messages/MessagesTh.php | 3 +- languages/messages/MessagesTk.php | 9 +- languages/messages/MessagesTl.php | 2566 ++++++++++++++++++++++++--- languages/messages/MessagesTo.php | 4 +- languages/messages/MessagesTr.php | 299 +++- languages/messages/MessagesTt_cyrl.php | 3 + languages/messages/MessagesUk.php | 5 +- languages/messages/MessagesVi.php | 2 +- languages/messages/MessagesVo.php | 11 +- languages/messages/MessagesWo.php | 47 +- languages/messages/MessagesXmf.php | 2 +- languages/messages/MessagesYi.php | 105 +- languages/messages/MessagesYo.php | 3 +- languages/messages/MessagesYue.php | 42 +- languages/messages/MessagesZh_classical.php | 44 +- languages/messages/MessagesZh_hans.php | 63 +- languages/messages/MessagesZh_hant.php | 52 +- maintenance/convertLinks.inc | 52 +- maintenance/initStats.inc | 22 +- maintenance/populateCategory.inc | 12 +- maintenance/populateParentId.inc | 18 +- maintenance/postgres/tables.sql | 2 +- maintenance/updaters.inc | 430 +++-- maintenance/userDupes.inc | 46 +- 127 files changed, 7210 insertions(+), 2810 deletions(-) diff --git a/RELEASE-NOTES b/RELEASE-NOTES index 311ed825..1071830b 100644 --- a/RELEASE-NOTES +++ b/RELEASE-NOTES @@ -2,11 +2,11 @@ For upgrade instructions please see the UPGRADE file in this directory. -== MediaWiki 1.13.3 == +== MediaWiki 1.13.4 == -December 15, 2008 +February 7, 2009 -This is a security release of the Summer 2008 snapshot release of MediaWiki. +This is a security update to the Summer 2008 snapshot release of MediaWiki. MediaWiki is now using a "continuous integration" development model with quarterly snapshot releases. The latest development code is always kept @@ -19,6 +19,21 @@ will be made on the development trunk and appear in the next quarterly release. Those wishing to use the latest code instead of a branch release can obtain it from source control: http://www.mediawiki.org/wiki/Download_from_SVN +== Changes since 1.13.3 == + +A number of cross-site scripting (XSS) security vulnerabilities were discovered +in the web-based installer (config/index.php). These vulnerabilities all +require a live installer -- once the installer has been used to install a wiki, +it is deactivated. + +Note that cross-site scripting vulnerabilities can be used to attack any website +in the same cookie domain. So if you have an uninstalled copy of MediaWiki on +the same site as an active web service, MediaWiki could be used to attack the +active service. + +If you are hosting an old copy of MediaWiki that you have never installed, you +are advised to remove it from the web. + == Changes since 1.13.2 == David Remahl of Apple's Product Security team has identified a number of diff --git a/config/index.php b/config/index.php index e76e6c7e..cef32248 100644 --- a/config/index.php +++ b/config/index.php @@ -84,7 +84,8 @@ $ourdb['mssql']['rootuser'] = 'administrator'; - MediaWiki <?php echo( $wgVersion ); ?> Installation + + MediaWiki <?php echo htmlspecialchars( $wgVersion ); ?> Installation