-----BEGIN PGP SIGNED MESSAGE----- Hash: SHA512 Format: 1.8 Date: Tue, 11 Oct 2022 23:47:45 CEST Source: mediawiki Architecture: source Version: 1:1.31.16-1+deb10u4 Distribution: buster-security Urgency: high Maintainer: Kunal Mehta <legoktm@debian.org> Changed-By: Markus Koschany <apo@debian.org> Checksums-Sha1: 1bb7047f5b69f3b9d50f67f6cebb73358b696790 2534 mediawiki_1.31.16-1+deb10u4.dsc 7c1054e71ace76dbc7f5a0d747b55ef8eb49bdd1 116872 mediawiki_1.31.16-1+deb10u4.debian.tar.xz e127b40bac9929803237ba2b2a4853c8ab6d08cd 6856 mediawiki_1.31.16-1+deb10u4_amd64.buildinfo Checksums-Sha256: f2b253c5c7f3bfe5de7aa6afe7c046479c225e3407199daf741cbb34c973569c 2534 mediawiki_1.31.16-1+deb10u4.dsc d2824278c4194daaaa86238df8102fd9b2d1d4729de23acf1082a4f2258ffd76 116872 mediawiki_1.31.16-1+deb10u4.debian.tar.xz 690fe28f2451d5045e2f65aa6462a1c20ac7fa836b99e57f9730b9f702b6cbbd 6856 mediawiki_1.31.16-1+deb10u4_amd64.buildinfo Changes: mediawiki (1:1.31.16-1+deb10u4) buster-security; urgency=high . * Non-maintainer upload by the LTS team. * Fix CVE-2022-41767: reassignEdits doesn't update results in an IP range check on Special:Contributions * Fix CVE-2022-41765: HTMLUserTextField exposes existence of hidden users Files: 31600ec0a864d2d4254fa762b1f1b0cd 2534 web optional mediawiki_1.31.16-1+deb10u4.dsc bfcf3caa21cd3cc9fd7595e85e671f0b 116872 web optional mediawiki_1.31.16-1+deb10u4.debian.tar.xz 0537215bd34cf5074a910e147a4e63c1 6856 web optional mediawiki_1.31.16-1+deb10u4_amd64.buildinfo -----BEGIN PGP SIGNATURE----- iQKjBAEBCgCNFiEErPPQiO8y7e9qGoNf2a0UuVE7UeQFAmNF5JJfFIAAAAAALgAo aXNzdWVyLWZwckBub3RhdGlvbnMub3BlbnBncC5maWZ0aGhvcnNlbWFuLm5ldEFD RjNEMDg4RUYzMkVERUY2QTFBODM1RkQ5QUQxNEI5NTEzQjUxRTQPHGFwb0BkZWJp YW4ub3JnAAoJENmtFLlRO1HkDKcP/Rp7EjbBSkKsYUIp+a17gPY+hvfXzUtEKc0m qdshia6EbMOkXEwpT1H2DBHJhQntTBwQEsnn4+aC3aAA58d++RnUmpgs7fPS+N46 jN6k6q8E6QE0wAMufB9UygPQL3r2mATL72ItPJNNjSSaigtrx0v5o06Sym8ZZD4C NV3Q7hqr5njYtY2tUb5CXVMeu1WOeFUVTrkIbTNkNV9W61zMhDC8IfMUl7P0CYLO QWjJN6wWe9mhTlEJLMlzq3ZsYcde3aXjZz3emOvr9ULZdxJZDiK1RWkQCMrst1fx I1CXCxhz1oM3ydC60lIngIi1Dc91ObExYUjjAFw+kjFStXwZ5bxBnfCp7+LklVwu +OBQbFFyyiMm/VEKvSSSy/VuX9JZrKgxY1ONjjQMi9yaGfjiJ4MuHE3rZ7sPQaLe xoZ5qpidHZr+Ior1kF8wbxspZllO/FViHcUsSQnEVa5gLlnWu/thHcqTvTCaZacp LBGCtgfQvruW7VsI2YAj/w0yW7tRLxlIPzIlLu7p6/pZ15lIJVxbWtj1dcu2EY3Q +RwUa6bIk/HMq7JYvwrPDvtJcEs+o3KfDat2K4wPaJoBcppd5GoXLu3M1fDqot4B hArN1K7OQ3BKe5KNcZ/klXFhfrXdQhOtQiD0qOdz6Tmiut2Ls1yz4OrTx8/CI/pk SDqW68n6 =+M05 -----END PGP SIGNATURE-----