Re: [Foundation-l] Security holes in Mediawiki

2009-09-15 Thread Andrew Gray
2009/9/15 Gregory Kohs : > I was sort of surprised to learn today that Mediawiki software has had 37 > security holes identified: > > http://akahele.org/2009/09/false-sense-of-security/ > > Are most of these patched now, or are they still open?  If still open, is > the Foundation making site & user

Re: [Foundation-l] Security holes in Mediawiki

2009-09-15 Thread Domas Mituzas
Hello Gregory, > I was sort of surprised to learn today that Mediawiki software has > had 37 > security holes identified: Why would you be surprised? It is web software, that allows _most_ flexibility for its users, you can expect most problems because of that, especially in XSS area. On t

Re: [Foundation-l] Security holes in Mediawiki

2009-09-15 Thread George Herbert
On Tue, Sep 15, 2009 at 10:38 AM, Gregory Kohs wrote: > I was sort of surprised to learn today that Mediawiki software has had 37 > security holes identified: > > http://akahele.org/2009/09/false-sense-of-security/ > > Are most of these patched now, or are they still open?  If still open, is > the

[Foundation-l] Security holes in Mediawiki

2009-09-15 Thread Gregory Kohs
I was sort of surprised to learn today that Mediawiki software has had 37 security holes identified: http://akahele.org/2009/09/false-sense-of-security/ Are most of these patched now, or are they still open? If still open, is the Foundation making site & user security more of a priority in 2010?