pkgsrc-Changes-HG archive

[Date Prev][Date Next][Thread Prev][Thread Next][Date Index][Thread Index][Old Index]

[pkgsrc/trunk]: pkgsrc/www/mediawiki Update to 1.24.1(security update)



details:   https://anonhg.NetBSD.org/pkgsrc/rev/aecb947421fd
branches:  trunk
changeset: 643471:aecb947421fd
user:      wen <wen%pkgsrc.org@localhost>
date:      Sat Dec 20 02:26:59 2014 +0000

description:
Update to 1.24.1(security update)

Upstream changes:
MediaWiki 1.24.1
This is a security and maintenance release of the MediaWiki 1.24 branch.

Changes since 1.24.0
(bug T76686) [SECURITY] thumb.php outputs wikitext message as raw HTML, which could lead to xss. Permission to edit MediaWiki namespace is required to exploit this.
(bug T77028) [SECURITY] Malicious site can bypass CORS restrictions in $wgCrossSiteAJAXdomains in API calls if it only included an allowed domain as part of its name.
(bug T74222) The original patch for T74222 was reverted as unnecessary.
Fixed a couple of entries in RELEASE-NOTES-1.24.
(bug T76168) OutputPage: Add accessors for some protected properties.
(bug T74834) Make 1.24 branch directly installable under PostgreSQL.

diffstat:

 www/mediawiki/Makefile |  5 ++---
 www/mediawiki/PLIST    |  3 ++-
 www/mediawiki/distinfo |  8 ++++----
 3 files changed, 8 insertions(+), 8 deletions(-)

diffs (56 lines):

diff -r 1cae40a3220a -r aecb947421fd www/mediawiki/Makefile
--- a/www/mediawiki/Makefile    Fri Dec 19 20:46:33 2014 +0000
+++ b/www/mediawiki/Makefile    Sat Dec 20 02:26:59 2014 +0000
@@ -1,4 +1,4 @@
-# $NetBSD: Makefile,v 1.49 2014/11/29 05:08:33 wen Exp $
+# $NetBSD: Makefile,v 1.50 2014/12/20 02:26:59 wen Exp $
 
 DISTNAME=      mediawiki-${VER}.${PVER}
 CATEGORIES=    www
@@ -22,7 +22,7 @@
 .include "options.mk"
 
 VER=                   1.24
-PVER=                  0
+PVER=                  1
 
 APACHE_USER?=          www
 APACHE_GROUP?=         www
@@ -72,7 +72,6 @@
 SUBST_STAGE.python=    post-patch
 SUBST_MESSAGE.python=  Fixing python path
 SUBST_FILES.python+=   extensions/ConfirmEdit/captcha.py
-+SUBST_FILES.python+=  maintenance/cssjanus/cssjanus.py maintenance/cssjanus/csslex.py
 SUBST_SED.python=      -e "s,/usr/bin/python,${PYTHONBIN},"
 
 SUBST_CLASSES+=                python2
diff -r 1cae40a3220a -r aecb947421fd www/mediawiki/PLIST
--- a/www/mediawiki/PLIST       Fri Dec 19 20:46:33 2014 +0000
+++ b/www/mediawiki/PLIST       Sat Dec 20 02:26:59 2014 +0000
@@ -1,4 +1,4 @@
-@comment $NetBSD: PLIST,v 1.21 2014/11/29 05:08:33 wen Exp $
+@comment $NetBSD: PLIST,v 1.22 2014/12/20 02:26:59 wen Exp $
 share/examples/mediawiki/mediawiki.conf
 share/mediawiki/COPYING
 share/mediawiki/CREDITS
@@ -5445,6 +5445,7 @@
 share/mediawiki/maintenance/postgres/compare_schemas.pl
 share/mediawiki/maintenance/postgres/mediawiki_mysql2postgres.pl
 share/mediawiki/maintenance/postgres/tables.sql
+share/mediawiki/maintenance/postgres/update-keys.sql
 share/mediawiki/maintenance/preprocessDump.php
 share/mediawiki/maintenance/preprocessorFuzzTest.php
 share/mediawiki/maintenance/protect.php
diff -r 1cae40a3220a -r aecb947421fd www/mediawiki/distinfo
--- a/www/mediawiki/distinfo    Fri Dec 19 20:46:33 2014 +0000
+++ b/www/mediawiki/distinfo    Sat Dec 20 02:26:59 2014 +0000
@@ -1,5 +1,5 @@
-$NetBSD: distinfo,v 1.36 2014/11/29 05:08:33 wen Exp $
+$NetBSD: distinfo,v 1.37 2014/12/20 02:26:59 wen Exp $
 
-SHA1 (mediawiki-1.24.0.tar.gz) = be618e04a0f3db8e3b977936eea2b42388a64609
-RMD160 (mediawiki-1.24.0.tar.gz) = 09d588e64059a7e19f4a53fe66c7ec84d52c0b40
-Size (mediawiki-1.24.0.tar.gz) = 20726660 bytes
+SHA1 (mediawiki-1.24.1.tar.gz) = 9ad18d6f432bb77a27d5d3145278a296b15186db
+RMD160 (mediawiki-1.24.1.tar.gz) = 2ae8706ec248947a1da78f498f4991e81c55e1fb
+Size (mediawiki-1.24.1.tar.gz) = 20725572 bytes



Home | Main Index | Thread Index | Old Index