Gentoo Websites Logo
Go to: Gentoo Home Documentation Forums Lists Bugs Planet Store Wiki Get Gentoo!
Bug 121512 - www-apps/mediawiki Possible comment DoS
Summary: www-apps/mediawiki Possible comment DoS
Status: RESOLVED FIXED
Alias: None
Product: Gentoo Security
Classification: Unclassified
Component: Vulnerabilities (show other bugs)
Hardware: All Linux
: High minor
Assignee: Gentoo Security
URL: http://sourceforge.net/project/showno...
Whiteboard: B3 [noglsa] DerCorny
Keywords:
Depends on:
Blocks:
 
Reported: 2006-02-04 00:56 UTC by Sune Kloppenborg Jeppesen (RETIRED)
Modified: 2006-03-07 17:18 UTC (History)
2 users (show)

See Also:
Package list:
Runtime testing required: ---


Attachments

Note You need to log in before you can comment on or make changes to this bug.
Description Sune Kloppenborg Jeppesen (RETIRED) gentoo-dev 2006-02-04 00:56:13 UTC
Release Name: MediaWiki 1.4.14
Notes:
= MediaWiki release notes =

Security reminder: MediaWiki does not require PHP's register_globals
setting since version 1.2.0. If you have it on, turn it *off* if you can.

== MediaWiki 1.4.14 ==

(released January 19, 2006)

MediaWiki 1.4.14 is a security and bugfix maintenance release.

A bug in edit comment formatting could send PHP into an infinite loop
if certain malformed links were included. In most installations, this
would cause the script to fail after PHP's 30-second failsafe timeout.

For several other minor fixes, see the complete changelog at the end
of this file.
Comment 1 Stefan Cornelius (RETIRED) gentoo-dev 2006-02-04 04:52:20 UTC
web-apps please bump, thanks
Comment 2 Thierry Carrez (RETIRED) gentoo-dev 2006-02-26 03:23:44 UTC
trapni: could you bump to 1.4.14 and/or tell us if one of the 1.5-series is fixed and ready to be stableized ?
Comment 3 Christian Parpart (RETIRED) gentoo-dev 2006-03-05 23:09:36 UTC
(In reply to comment #2)
> trapni: could you bump to 1.4.14 and/or tell us if one of the 1.5-series is
> fixed and ready to be stableized ?

I'm going to bump 1.4.14 anyways (i've just been off for a wile);
1.5 series in fact already *is* stable - but I kept 1.3/1.4 in for those who don't wanna upgrade (yet), though, I'm planning in removing 1.3 soon anyways.
Comment 4 Christian Parpart (RETIRED) gentoo-dev 2006-03-06 20:16:24 UTC
bumped, thanks.
Comment 5 Stefan Cornelius (RETIRED) gentoo-dev 2006-03-07 07:35:21 UTC
Sorry trapni, security first has to vote if we need a GLSA here. I tend to vote no since PHP should recover after the 30s timeout.
Comment 6 Thierry Carrez (RETIRED) gentoo-dev 2006-03-07 10:08:50 UTC
Voting no and closing.
Comment 7 Christian Parpart (RETIRED) gentoo-dev 2006-03-07 17:18:21 UTC
man, sorry. I do always forget the security voting stuff. sorry :o)