Gentoo Websites Logo
Go to: Gentoo Home Documentation Forums Lists Bugs Planet Store Wiki Get Gentoo!
Bug 928349 - www-apps/mediawiki-{1.41.1,1.40.3,1.39.7}: please stabilize (security)
Summary: www-apps/mediawiki-{1.41.1,1.40.3,1.39.7}: please stabilize (security)
Status: RESOLVED FIXED
Alias: None
Product: Gentoo Linux
Classification: Unclassified
Component: Stabilization (show other bugs)
Hardware: All Linux
: Normal normal (vote)
Assignee: Gentoo Web Application Packages Maintainers
URL:
Whiteboard:
Keywords: ALLARCHES, CC-ARCHES, SECURITY, STABLEREQ
Depends on:
Blocks:
 
Reported: 2024-04-01 07:46 UTC by Miroslav Šulc
Modified: 2024-04-01 16:42 UTC (History)
0 users

See Also:
Package list:
www-apps/mediawiki-1.41.1 www-apps/mediawiki-1.40.3 www-apps/mediawiki-1.39.7
Runtime testing required: ---
nattka: sanity-check+


Attachments

Note You need to log in before you can comment on or make changes to this bug.
Description Miroslav Šulc gentoo-dev 2024-04-01 07:46:09 UTC
== Security fixes ==

* (T355538, CVE-2024-PENDING) SECURITY: XSS in edit summary parser.
* (T357760, CVE-2024-PENDING) SECURITY: Denial of service vector via GET
request to Special:MovePage on pages with thousands of subpages.


commit 6925a2bca319871a7d27d3cb1bbf77b26232f225
Author: Miroslav Šulc <fordfrog@gentoo.org>
Date:   Fri Mar 29 10:11:02 2024 +0100

    www-apps/mediawiki: bump to 1.39.7
    
    Signed-off-by: Miroslav Šulc <fordfrog@gentoo.org>

commit cf7744d2e5146d81ae9864ac45928a9a86982352
Author: Miroslav Šulc <fordfrog@gentoo.org>
Date:   Fri Mar 29 10:09:29 2024 +0100

    www-apps/mediawiki: bump to 1.40.3
    
    Signed-off-by: Miroslav Šulc <fordfrog@gentoo.org>

commit f4f33fa6abe9f6c4b8193fe13dcc463efcbff1b3
Author: Miroslav Šulc <fordfrog@gentoo.org>
Date:   Fri Mar 29 10:07:52 2024 +0100

    www-apps/mediawiki: bump to 1.41.1
    
    Signed-off-by: Miroslav Šulc <fordfrog@gentoo.org>
Comment 1 Arthur Zamarin archtester Gentoo Infrastructure gentoo-dev Security 2024-04-01 13:50:19 UTC
amd64 ppc [x86] (ALLARCHES) done

all arches done
Comment 2 Larry the Git Cow gentoo-dev 2024-04-01 16:42:21 UTC
The bug has been referenced in the following commit(s):

https://gitweb.gentoo.org/repo/gentoo.git/commit/?id=3ab17e8e74af2e426cb17f85065772327faf5d20

commit 3ab17e8e74af2e426cb17f85065772327faf5d20
Author:     Miroslav Šulc <fordfrog@gentoo.org>
AuthorDate: 2024-04-01 16:42:04 +0000
Commit:     Miroslav Šulc <fordfrog@gentoo.org>
CommitDate: 2024-04-01 16:42:04 +0000

    www-apps/mediawiki: dropped obsolete and vulnerable
    
    Bug: https://bugs.gentoo.org/928349
    Signed-off-by: Miroslav Šulc <fordfrog@gentoo.org>

 www-apps/mediawiki/Manifest                |  3 -
 www-apps/mediawiki/mediawiki-1.39.6.ebuild | 90 -----------------------------
 www-apps/mediawiki/mediawiki-1.40.2.ebuild | 92 ------------------------------
 www-apps/mediawiki/mediawiki-1.41.0.ebuild | 92 ------------------------------
 4 files changed, 277 deletions(-)