Software Update: MediaWiki 1.5.4

Spread the love

MediaWiki is a Wiki engine released under the GPL license that can be used to create and manage content. It is used, among others, for the websites of the Wikimedia Foundation, such as Wikipedia, Wikipedia, Wikisource, Wikibooks and Wikiquote. The appearance can be completely adjusted to your own wishes with the help of skins this page are some examples of different skins. The developers patched a security vulnerability and applied some additional maintenance that allowed version 1.5.4 to be released. The included announcement looks like this:

MediaWiki 1.5.4 is a security and bug fix maintenance release.

A hard-coded internal placeholder string has been replaced with a random one. This closes a hole where security checks in inline style attributes could be bypassed, injecting JavaScript code that could execute in Microsoft Internet Explorer.

Other browsers would not be vulnerable.

Several minor fixes are included in this release, most notably a fix to clear the “you have new messages” flag properly for usernames containing spaces when e-mail notification is enabled.

Changes since 1.5.3:

  • (bug 3805) Clear ‘new messages’ flag properly in enotif mode for usernames containing spaces
  • (bug 2714) Backlink from special:whatlinkshere was hard set as ‘existing’
  • (bug 4249) Typo in entities2literals.pl
  • (bug 4233) Update for japanese language
  • (bug 4279) Small correction to LanguageDa.php
  • (bug 4267) Switch dv sd ug ks arc languages ​​to RTL
  • (bug 3991) Allow the operation of wikicode on Protect move only text
  • Added AutoAuthenticate hook for external User object suppliers
  • Parser internal placeholder string now fully randomized for safety

Version number 1.5.4
Website sourceforge
Download
File size

2.18MB

License type GPL
You might also like