mediawiki (1:1.19.20+dfsg-0+deb7u3) wheezy-security; urgency=medium * CVE-2014-9277: Fix regression introduced by previous patch. * Add patch fixing T76686: thumb.php outputs wikitext message as raw HTML, which could lead to xss. Permission to edit MediaWiki namespace is required to exploit this. -- Sebastien Delafond Sun, 21 Dec 2014 13:03:27 +0100 mediawiki (1:1.19.20+dfsg-0+deb7u2) wheezy-security; urgency=medium * Non-maintainer upload by the Security Team. * CVE-2014-9277: The mangling in OutputHandler.php poses a potentially severe security problem for API clients written in PHP, in that format=php is affected. -- Sebastien Delafond Wed, 10 Dec 2014 23:26:48 +0100 mediawiki (1:1.19.20+dfsg-0+deb7u1) wheezy-security; urgency=high * New upstream security release: - CVE-2014-7295 (bug 70672) SECURITY: OutputPage: Remove separation of css and js module allowance. -- Thorsten Glaser Thu, 02 Oct 2014 10:57:16 +0200 mediawiki (1:1.19.19+dfsg-0+deb7u1) wheezy-security; urgency=medium * Remove Romain Beauxis’ bouncing eMail address * Acknowledge NMU (1:1.19.18+dfsg-0+deb7u1) – thanks! * New upstream security and maintenance release: - (bug 69008) SECURITY: Enhance CSS filtering in SVG files. Filter