===================================================================== CERT-Renater Note d'Information No. 2014/VULN113 _____________________________________________________________________ DATE : 25/04/2014 HARDWARE PLATFORM(S): / OPERATING SYSTEM(S): Systems running MediaWiki version prior to 1.22.6, 1.21.9. ====================================================================== http://lists.wikimedia.org/pipermail/mediawiki-announce/2014-April/000149.html ______________________________________________________________________ Hello everyone, I would like to announce the release of MediaWiki 1.22.6 and 1.21.9. This is a regular security and maintenance release. Download links are given at the end of this email. Please note there is no new release of the 1.19 branch, as it is not affected by the security issue. == Security == * (bug 63251) SECURITY: escape sortKey in pageInfo. == Bugfixes in 1.21.9 == * (bug 58640) Fixed a compatibility issue with PCRE 8.34 that caused pages to appear blank or with missing text. Full release notes for 1.22.6: Full release notes for 1.21.9: Public keys: ********************************************************************** 1.22.6 ********************************************************************** Download: http://releases.wikimedia.org/mediawiki/1.22/mediawiki-1.22.6.tar.gz Patch to previous version (1.22.5): http://releases.wikimedia.org/mediawiki/1.22/mediawiki-1.22.6.patch.gz GPG signatures: http://releases.wikimedia.org/mediawiki/1.22/mediawiki-core-1.22.6.tar.gz.sig http://releases.wikimedia.org/mediawiki/1.22/mediawiki-1.22.6.tar.gz.sig http://releases.wikimedia.org/mediawiki/1.22/mediawiki-1.22.6.patch.gz.sig Note: There is no i18n patch as there are no changes in translation. ********************************************************************** 1.21.9 ********************************************************************** Download: http://releases.wikimedia.org/mediawiki/1.21/mediawiki-1.21.9.tar.gz Patch to previous version (1.21.8): http://releases.wikimedia.org/mediawiki/1.21/mediawiki-1.21.9.patch.gz GPG signatures: http://releases.wikimedia.org/mediawiki/1.21/mediawiki-core-1.21.9.tar.gz.sig http://releases.wikimedia.org/mediawiki/1.21/mediawiki-1.21.9.tar.gz.sig http://releases.wikimedia.org/mediawiki/1.21/mediawiki-1.21.9.patch.gz.sig Note: There is no i18n patch as there are no changes in translation. Markus Glaser (Release Management Team) ========================================================= Serveur de référence du CERT-Renater https://services.renater.fr/ssi/ ========================================================== + CERT-RENATER | tel : 01-53-94-20-44 + + 23 - 25 Rue Daviel | fax : 01-53-94-20-41 + + 75013 Paris | email: cert@support.renater.fr + ==========================================================