The patches touches import of pages and uploads, both have been tested to work in general. I'm sorry I don't have a testcase to verify the security problems.
The package in gutsy is done in a way making it impossible to patch. The package in dapper is ancient, and already misses a huge amount of security patches, so don't think it is worth it. ** Changed in: mediawiki (Ubuntu) Assignee: Andreas Wenning (andreas-wenning) => (unassigned) Status: In Progress => New ** CVE added: http://www.cve.mitre.org/cgi- bin/cvename.cgi?name=2008-5249 ** CVE added: http://www.cve.mitre.org/cgi- bin/cvename.cgi?name=2008-5250 ** CVE added: http://www.cve.mitre.org/cgi- bin/cvename.cgi?name=2008-5252 ** Visibility changed to: Public -- Multiple security problems found: [CVE-2008-5249] [CVE-2008-5250] [CVE-2008-5252] https://bugs.launchpad.net/bugs/323842 You received this bug notification because you are a member of Ubuntu Bugs, which is subscribed to Ubuntu. -- ubuntu-bugs mailing list ubuntu-bugs@lists.ubuntu.com https://lists.ubuntu.com/mailman/listinfo/ubuntu-bugs