summaryrefslogtreecommitdiff
path: root/editors
diff options
context:
space:
mode:
authorwen <wen>2015-10-18 03:11:26 +0000
committerwen <wen>2015-10-18 03:11:26 +0000
commita1e19d5cf03413cd2695ba969e83143178e8866f (patch)
tree280b4a79e9169b04a9d22b0722433dc7aa79b0ab /editors
parent5c6d92ad65509a72d0fecccf430bf8e201e3ae9a (diff)
downloadpkgsrc-a1e19d5cf03413cd2695ba969e83143178e8866f.tar.gz
Update to 1.25.3
Upstream changes: == Security fixes == * Wikipedia user RobinHood70 reported two issues in the chunked upload API. The API failed to correctly stop adding new chunks to the upload when the reported size was exceeded (T91203), allowing a malicious users to upload add an infinite number of chunks for a single file upload. Additionally, a malicious user could upload chunks of 1 byte for very large files, potentially creating a very large number of files on the server's filesystem (T91205). <https://phabricator.wikimedia.org/T91203> <https://phabricator.wikimedia.org/T91205> * Internal review discovered that it is not possible to throttle file uploads. <https://phabricator.wikimedia.org/T91850> * Internal review discovered a missing authorization check when removing suppression from a revision. This allowed users with the 'viewsuppressed' user right but not the appropriate 'suppressrevision' user right to unsuppress revisions. <https://phabricator.wikimedia.org/T95589> * Richard Stanway from teamliquid.net reported that thumbnails of PNG files generated with ImageMagick contained the local file path in the image metadata. <https://phabricator.wikimedia.org/T108616> == Bug Fixes in 1.25.3 == * Fix having multiple callbacks for a single hook. <https://phabricator.wikimedia.org/T98975> * maintenance/refreshLinks.php did not always remove all links pointing to nonexistent pages. <https://phabricator.wikimedia.org/T107632> * $wgEmergencyContact and $wgPasswordSender now use their default value if set to an empty string. <https://phabricator.wikimedia.org/T104142> * Provide fallbacks for use of mb_convert_encoding() in HtmlFormatter. It was causing an error when accessing the api help page if the mbstring PHP extension was not installed. <https://phabricator.wikimedia.org/T62174> * Confirmation emails would sometimes contain invalid codes. <https://phabricator.wikimedia.org/T105896> * Fixed edit stash inclusion queries. <https://phabricator.wikimedia.org/T105597>
Diffstat (limited to 'editors')
0 files changed, 0 insertions, 0 deletions