From 364b55264cf4daafa7a5d353f9be71864307a0d6 Mon Sep 17 00:00:00 2001 From: Pierre Schmitz Date: Thu, 25 Sep 2014 13:59:03 +0200 Subject: Update to MediaWiki 1.22.11 --- RELEASE-NOTES-1.22 | 10 +++++ includes/DefaultSettings.php | 2 +- includes/Sanitizer.php | 51 ++++++++++++++------- includes/XmlTypeCheck.php | 57 +++++++++++++++++++++-- includes/upload/UploadBase.php | 100 +++++++++++++++++++++++++++++++++++++---- 5 files changed, 190 insertions(+), 30 deletions(-) diff --git a/RELEASE-NOTES-1.22 b/RELEASE-NOTES-1.22 index 3479fbca..34ced35a 100644 --- a/RELEASE-NOTES-1.22 +++ b/RELEASE-NOTES-1.22 @@ -3,6 +3,16 @@ Security reminder: MediaWiki does not require PHP's register_globals. If you have it on, turn it '''off''' if you can. +== MediaWiki 1.22.11 == + +This is a security release of the MediaWiki 1.22 branch. + +=== Changes since 1.22.10 === +* (bug 69008) SECURITY: Enhance CSS filtering in SVG files. Filter