Changes: mediawiki (1:1.19.20+dfsg-0+deb7u2) wheezy-security; urgency=medium * Non-maintainer upload by the Security Team. * CVE-2014-9277: The <cross-domain-policy> mangling in OutputHandler.php poses a potentially severe security problem for API clients written in PHP, in that format=php is affected. -- Sebastien Delafond <[email protected]> Wed, 10 Dec 2014 23:26:48 +0100