]> git.vanrenterghem.biz Git - git.ikiwiki.info.git/blobdiff - debian/changelog
htmlscrubber: Security fix: In data:image/* uris, only allow a few whitelisted image...
[git.ikiwiki.info.git] / debian / changelog
index fdbcfd7f4113927aa4b0a434740250cb3dc791e5..c01b697e367e3c80b1d97b93a595d745f510c0e5 100644 (file)
@@ -1,7 +1,14 @@
-ikiwiki (2.53.4) UNRELEASED; urgency=low
+ikiwiki (2.53.5) stable-security; urgency=high
+
+  * htmlscrubber: Security fix: In data:image/* uris, only allow a few
+    whitelisted image types. No svg.
+
+ -- Joey Hess <joeyh@debian.org>  Fri, 12 Mar 2010 15:19:29 -0500
+
+ikiwiki (2.53.4) stable-security; urgency=high
 
   * teximg: Replace the insufficient blacklist with the built-in security
-    mechanisms of TeX.
+    mechanisms of TeX. (CVE-2009-2944)
   * img: Don't generate new verison of image if it is scaled to be
     larger in either dimension.