Due to a mistake in packaging, the releases 1.27.2 and 1.28.1 did not contain the fix for SyntaxHighlight_GeSHi. This new release does contain that fix.. --------------------------------------------------------------------------------Fedora Update Notification FEDORA-2017-2643ef1cad 2017-05-12 04:05:28.497241 --------------------------------------------------------------------------------Name : mediawiki Product : Fedora 25 Version : 1.27.3 Release : 1.fc25 URL : https://www.mediawiki.org/wiki/MediaWiki Summary : A wiki engine Description : MediaWiki is the software used for Wikipedia and the other Wikimedia Foundation websites. Compared to other wikis, it has an excellent range of features and support for high-traffic websites using multiple servers This package supports wiki farms. Read the instructions for creating wiki instances under /usr/share/doc/mediawiki/README.RPM. Remember to remove the config dir after completing the configuration. --------------------------------------------------------------------------------Update Information: Due to a mistake in packaging, the releases 1.27.2 and 1.28.1 did not contain the fix for SyntaxHighlight_GeSHi. This new release does contain that fix. --------------------------------------------------------------------------------References: [ 1 ] Bug #1448111 - CVE-2017-0372 mediawiki: SyntaxHighlight extension allows injection of arbitrary Pygments options [fedora-all] https://bugzilla.redhat.com/show_bug.cgi?id=1448111 --------------------------------------------------------------------------------This update can be installed with the "dnf" update program. Use su -c 'dnf upgrade mediawiki' at the command line. For more information, refer to the dnf documentation available at https://dnf.readthedocs.io/en/latest/command_ref.html All packages are signed with the Fedora Project GPG key. More details on the GPG keys used by the Fedora Project can be foundat https://fedoraproject.org/security/ -------------------------------------------------------------------------------- _______________________________________________ package-announce mailing list --
Get the latest Linux and open source security news straight to your inbox.