X-Git-Url: http://git.vanrenterghem.biz/git.ikiwiki.info.git/blobdiff_plain/41122048b924ffa16ef8e1f77730f15b455733b0..b2fd4f9b254610283d3fa6944ea73941c2045769:/doc/security.mdwn?ds=inline diff --git a/doc/security.mdwn b/doc/security.mdwn index ba3eac187..3924186c2 100644 --- a/doc/security.mdwn +++ b/doc/security.mdwn @@ -420,10 +420,10 @@ later that day, in version 2.70. The fix was backported to testing as version ## Insufficient blacklisting in teximg plugin -Josh Tripplet discovered on 28 Aug 2009 that the teximg plugin's +Josh Triplett discovered on 28 Aug 2009 that the teximg plugin's blacklisting of insecure TeX commands was insufficient; it could be bypassed and used to read arbitrary files. This was fixed by enabling TeX configuration options that disallow unsafe TeX commands. The fix was released on 30 Aug 2009 in version 3.1415926, and was backported to stable in version 2.53.4. If you use the teximg plugin, -I recommend upgrading. +I recommend upgrading. ([[!cve CVE-2009-2944]])