X-Git-Url: http://git.vanrenterghem.biz/git.ikiwiki.info.git/blobdiff_plain/96eb9bb3fa1d805df967f44d13876f57b8ea121d..8f788fa1e1489c27959f161ed46f96ddf009d0ee:/debian/changelog diff --git a/debian/changelog b/debian/changelog index adbffb9c0..d2dbe592d 100644 --- a/debian/changelog +++ b/debian/changelog @@ -1,4 +1,46 @@ -ikiwiki (1.33) UNRELEASED; urgency=low +ikiwiki (1.33.4) stable-security; urgency=high + + * htmlscrubber security fix: Block javascript in uris. Closes: #465110 + * meta: Check that the urls provided for authorurl, permalink, and openid + are safe and can't contain javascript. + * Add htmlscrubber test suite. + * Thanks to Josh Triplett for pointing out the holes and for his help + in implementing and checking fixes. + + -- Joey Hess Sun, 10 Feb 2008 13:34:28 -0500 + +ikiwiki (1.33.3) testing-proposed-updates; urgency=medium + + * Fix a security hole that allowed insertion of unsafe content via the meta + plugins's support for inserting html link and meta tags. Now such content + is passed through the htmlscrubber like everything else. + * Unfortunatly, that means that some valid uses of those tags are no longer + usable, and special case methods needed to be added for including + stylesheets, and for doing openid delegation. If you use either of these + in your wiki, it will need to be modified. See the meta plugin docs + for details. + + -- Joey Hess Wed, 21 Mar 2007 14:56:48 -0400 + +ikiwiki (1.33.2) testing-proposed-updates; urgency=medium + + * Backport fix for a security hole that allowed a web user to insert + arbitrary html in the title of a page due to missing escaping of + titles in the meta plugin. + * Fix examples directory location. + + -- Joey Hess Wed, 21 Mar 2007 01:55:02 -0400 + +ikiwiki (1.33.1) testing-proposed-updates; urgency=medium + + * Backport fix for a security hole that allowed a web user to edit images + and other non-page format files in the wiki. To exploit this, the file + already had to exist in the wiki, and the web user would need to somehow + use the web based editor to replace it with malicious content. + + -- Joey Hess Sat, 10 Feb 2007 15:30:12 -0500 + +ikiwiki (1.33) unstable; urgency=low * Fix issue with aggregate plugin updating expired pages. * Avoid syntax errors in templates used by the template plugin crashing @@ -13,8 +55,9 @@ ikiwiki (1.33) UNRELEASED; urgency=low FORM-SUBMIT unusable on customised formbuilder templates. For now, hardcode the submit buttons in editpage.tmpl instead of using the template variable, which is ok, since the buttons are static. + * Work with hyperestraier 1.4.9. - -- Joey Hess Fri, 10 Nov 2006 02:34:49 -0500 + -- Joey Hess Wed, 15 Nov 2006 18:32:26 -0500 ikiwiki (1.32) unstable; urgency=low