-ikiwiki (3.20141016.3) UNRELEASED; urgency=medium
+ikiwiki (3.20141016.4) UNRELEASED; urgency=high
+
+ * Reference CVE-2016-4561 in 3.20141016.3 changelog
+ * Security: force CGI::FormBuilder->field to scalar context where
+ necessary, avoiding unintended function argument injection
+ analogous to CVE-2014-1572.
+ - passwordauth: prevent authentication bypass via multiple name
+ parameters (OVE-20170111-0001)
+ - passwordauth: prevent userinfo forgery via repeated email
+ parameter (OVE-20170111-0001)
+ - comments, editpage: prevent commit metadata forgery
+ (CVE-2016-9646, OVE-20161226-0001)
+ - CGI, attachment, comments, editpage, notifyemail, passwordauth,
+ po, rename: harden against similar issues that are not believed
+ to be exploitable
+ * t/passwordauth.t: new automated test for OVE-20170111-0001
+ * Backport IkiWiki::Plugin::img from 3.20160905 to fix a regression
+ in 3.20141016.3:
+ - img: ignore the case of the extension when detecting image format,
+ fixing the regression that *.JPG etc. would not be displayed
+ (patch from Amitai Schleier)
+
+ -- Simon McVittie <smcv@debian.org> Wed, 11 Jan 2017 15:22:38 +0000
+
+ikiwiki (3.20141016.3) jessie-security; urgency=high
+ [ Simon McVittie ]
* img: stop ImageMagick trying to be clever if filenames contain a colon,
avoiding mis-processing
* HTML-escape error messages, in one case avoiding potential cross-site
- scripting (OVE-20160505-0012)
+ scripting (CVE-2016-4561, OVE-20160505-0012)
* Mitigate ImageMagick vulnerabilities such as CVE-2016-3714:
- img: force common Web formats to be interpreted according to extension,
so that "allowed_attachments: '*.jpg'" does what one might expect
- img: check that the magic number matches what we would expect from
the extension before giving common formats to ImageMagick
- -- Simon McVittie <smcv@debian.org> Thu, 05 May 2016 23:33:26 +0100
+ [ Joey Hess ]
+ * img: Add back support for SVG images, bypassing ImageMagick and
+ simply passing the SVG through to the browser, which is supported by all
+ commonly used browsers these days.
+ SVG scaling by img directives has subtly changed; where before
+ size=wxh would preserve aspect ratio, this cannot be done when passing
+ them through and so specifying both a width and height can change
+ the SVG's aspect ratio.
+
+ -- Simon McVittie <smcv@debian.org> Fri, 06 May 2016 07:55:49 +0100
ikiwiki (3.20141016.2) unstable; urgency=high