r67591 MediaWiki - Code Review archive

Repository:MediaWiki
Revision:r67590‎ | r67591 | r67592 >
Date:06:07, 8 June 2010
Author:tstarling
Status:deferred
Tags:
Comment:
(bug 23361) Documentation for ImageMagick escaping issue as requested.
Modified paths:
  • /branches/REL1_16/phase3/RELEASE-NOTES (modified) (history)

Diff [purge]

Index: branches/REL1_16/phase3/RELEASE-NOTES
@@ -81,6 +81,11 @@
8282 account" and "create by e-mail" features of [[Special:Userlogin]]
8383 * (bug 23687) Fixed XSS vulnerability affecting IE clients only, due to a CSS
8484 validation issue.
 85+* Fixed a DoS vulnerability in ImageMagick image scaling. ImageMagick
 86+ expanded wildcard characters "?" and "*" in image filenames, potentially
 87+ causing large numbers of images to be scaled in response to a single request.
 88+ The fix for this involves breaking the scaling of such image filenames until
 89+ ImageMagick 6.6.1-5 or later is deployed, see bug 23361 for more details.
8590
8691 === Changes since 1.16 beta 1 ===
8792

Status & tagging log