Bug#686330: mediawiki: Multiple security issues

2012-09-14 Thread Thorsten Glaser
On Thu, 13 Sep 2012, Moritz Muehlenhoff wrote: > On Fri, Aug 31, 2012 at 06:34:38PM +0200, Julien Cristau wrote: > > Can't answer without a diff. > > Mediawiki maintainers, what's the status? Oh, sorry. Other stuff made me forget this for too long. The diff between the two tarballs is over 10

Bug#686330: [Pkg-mediawiki-devel] Bug#686330: mediawiki: Multiple security issues

2012-09-13 Thread Platonides
On 13/09/12 18:01, Moritz Muehlenhoff wrote: > On Fri, Aug 31, 2012 at 06:34:38PM +0200, Julien Cristau wrote: >> On Fri, Aug 31, 2012 at 10:37:25 +0200, Thorsten Glaser wrote: >> >>> The Release Notes say that 1.19.2 is a security-fix release, >>> and does not list any unrelated changes. Question

Bug#686330: mediawiki: Multiple security issues

2012-09-13 Thread Moritz Muehlenhoff
On Fri, Aug 31, 2012 at 06:34:38PM +0200, Julien Cristau wrote: > On Fri, Aug 31, 2012 at 10:37:25 +0200, Thorsten Glaser wrote: > > > The Release Notes say that 1.19.2 is a security-fix release, > > and does not list any unrelated changes. Question is, (to the > > more seasoned MW packagers) can

Bug#686330: mediawiki: Multiple security issues

2012-08-31 Thread Julien Cristau
On Fri, Aug 31, 2012 at 10:37:25 +0200, Thorsten Glaser wrote: > The Release Notes say that 1.19.2 is a security-fix release, > and does not list any unrelated changes. Question is, (to the > more seasoned MW packagers) can we trust that, and (to the > Release Team) would it be acceptable to bump

Bug#686330: mediawiki: Multiple security issues

2012-08-31 Thread Thorsten Glaser
On Fri, 31 Aug 2012, Moritz Muehlenhoff wrote: > Please see here for more info: > http://www.gossamer-threads.com/lists/wiki/mediawiki/295767 Thanks. The Release Notes say that 1.19.2 is a security-fix release, and does not list any unrelated changes. Question is, (to the more seasoned MW packag

Bug#686330: mediawiki: Multiple security issues

2012-08-31 Thread Moritz Muehlenhoff
Package: mediawiki Severity: grave Tags: security Justification: user security hole Please see here for more info: http://www.gossamer-threads.com/lists/wiki/mediawiki/295767 No CVE IDs available yet. Cheers, Moritz -- To UNSUBSCRIBE, email to debian-bugs-rc-requ...@lists.debian.org w