Bug List: (This bug is not in your last search results)   Show last search results      Search page      Enter new bug
Bug#: 127971
Alias:
Product:
Component:
Status: RESOLVED
Resolution: FIXED
Assigned To: Gentoo Security <security@gentoo.org>
Hardware:
OS:
Version:
Priority:
Severity:
Reporter: BobCaTT <bugs@menfin.net>
Add CC:
CC:
Remove selected CCs
URL:
Summary:
Status Whiteboard:
Keywords:
Flags: Requestee:
 
 
  ()

Filename Description Type Creator Created Size Actions
Create a New Attachment (proposed patch, testcase, etc.) View All

Bug 127971 depends on: Show dependency tree
Bug 127971 blocks:

Additional Comments: (this is where you put emerge --info)


Not eligible to see or edit group visibility for this bug.






View Bug Activity   |   Format For Printing   |   XML   |   Clone This Bug


Description:   Opened: 2006-03-29 04:48 0000
Hello

mediawiki shoud be upgraded in the portage with the followings versions
- 1.5.8
- 1.4.15
- 1.3.18

As described on the homepage (http://www.mediawiki.org/wiki/MediaWiki) there
some html/xss injections.

Older versions may be removed from the portage ?

------- Comment #1 From Stefan Cornelius (RETIRED) 2006-03-29 06:17:59 0000 -------
hi web-apps, do you want to provide an ebuild for 1.4.15 or should we go for a
stable marking of 1.5.8?

------- Comment #2 From Christian Parpart 2006-03-29 09:17:12 0000 -------
I'd vote for both.

Although, I already bumped 1.5.8 as it came out, but I must have missed the
1.4.15 release.

1.4.15 is in the tree now as well. thanks for the notice :)

(I do not close this bug as it's kinda security-assigned, so please do so if
you feel fine with all)

------- Comment #3 From Stefan Cornelius (RETIRED) 2006-03-29 09:33:56 0000 -------
arches, please test and mark 1.4.15 or 1.5.8 stable, thank you.

------- Comment #4 From Stefan Cornelius (RETIRED) 2006-03-29 10:32:49 0000 -------
trapni, please dont bump security bugs directly to stable. Would you or
somebody from the arches team please remove the stable keywords for any arch
this wasnt tested on? Thanks.

------- Comment #5 From Christian Parpart 2006-03-29 11:00:58 0000 -------
um, yeah, okay - as it was a security (bugfix only) release, and 1.4.14 were
already marked stable I didn't mind in unstable-marking them all.

For amd64 I could speak that it runs just fine for the 1.5.x line as I'm using
it in production since it's out (w/o any problems so far).

------- Comment #6 From Mark Loeser 2006-03-29 18:07:20 0000 -------
Well, it looks like 1.4.15 is already stable on x86.

trapni: as stated, in the future please don't bump stuff straight to stable.

------- Comment #7 From Jason Wever (RETIRED) 2006-03-29 20:01:44 0000 -------
Removing SPARC as 1.4.15 works and was already keyworded stable

------- Comment #8 From Simon Stelling (RETIRED) 2006-03-30 01:54:09 0000 -------
trapni is in the amd64 team, so that works with me

------- Comment #9 From Stefan Cornelius (RETIRED) 2006-03-30 03:05:41 0000 -------
CVE-2006-1498

------- Comment #10 From Thierry Carrez (RETIRED) 2006-04-01 02:56:35 0000 -------
Bad Product/component

------- Comment #11 From nixnut 2006-04-01 07:21:49 0000 -------
1.4.15 tested and found ok on ppc, so the ppc keyword can stay. 

------- Comment #12 From Stefan Cornelius (RETIRED) 2006-04-01 07:32:36 0000 -------
ready for glsa decision. weak yes here, mainly because we issued GLSAs for XSS
in mediawiki in the past.

------- Comment #13 From Raphael Marichez 2006-04-01 07:43:44 0000 -------
(In reply to comment #12)
> ready for glsa decision. weak yes here, mainly because we issued GLSAs for XSS
> in mediawiki in the past.
> 

Last one was on 2005-07-20, AFAIK.

Vote 0.5 yes.

------- Comment #14 From Sune Kloppenborg Jeppesen 2006-04-01 10:48:56 0000 -------
Tend to vote YES on this one.

------- Comment #15 From Thierry Carrez (RETIRED) 2006-04-02 00:58:07 0000 -------
XSS and injection in publically-writeable websites (forums, wikis...) is evil.
So I vote yes.

------- Comment #16 From Stefan Cornelius (RETIRED) 2006-04-04 05:09:38 0000 -------
GLSA 200604-01

Thanks everybody.

Bug List: (This bug is not in your last search results)   Show last search results      Search page      Enter new bug