summaryrefslogtreecommitdiff
path: root/RELEASE-NOTES-1.20
diff options
context:
space:
mode:
authorPierre Schmitz <pierre@archlinux.de>2013-04-16 05:29:15 +0200
committerPierre Schmitz <pierre@archlinux.de>2013-04-16 05:29:15 +0200
commitd43bf442ab472de9ad9db6b62e9f7b02e580f466 (patch)
treeff4eeb631d4b5cce4789df92c905cc42b106a63d /RELEASE-NOTES-1.20
parent0edd6983ba69e8195fa7cade96eca27df9ebf237 (diff)
Update to MediaWiki 1.20.4
Diffstat (limited to 'RELEASE-NOTES-1.20')
-rw-r--r--RELEASE-NOTES-1.208
1 files changed, 8 insertions, 0 deletions
diff --git a/RELEASE-NOTES-1.20 b/RELEASE-NOTES-1.20
index a7197ec1..d03ca1fa 100644
--- a/RELEASE-NOTES-1.20
+++ b/RELEASE-NOTES-1.20
@@ -3,6 +3,14 @@
Security reminder: MediaWiki does not require PHP's register_globals
setting since version 1.2.0. If you have it on, turn it '''off''' if you can.
+== MediaWiki 1.20.4 ==
+
+This is a security release of the MediaWiki 1.20 branch.
+
+=== Changes since 1.20.3 ===
+* (bug 47251) SECURITY: Disable external entities in Import
+* (bug 46859) SECURITY: Disable external entities in XMLReader
+* (bug 46084) SECURITY: Sanitize $limitReport before outputting
== MediaWiki 1.20.3 ==