X-Git-Url: http://git.vanrenterghem.biz/git.ikiwiki.info.git/blobdiff_plain/b8fd31a2a3305aed41176f84377b108f679299fd..851cc6ca0d241e9167b8188102199190d5baed3c:/debian/changelog diff --git a/debian/changelog b/debian/changelog index 98d13376d..3dac4c400 100644 --- a/debian/changelog +++ b/debian/changelog @@ -1,3 +1,65 @@ +ikiwiki (3.20100815.8) stable-security; urgency=low + + * ikiwiki-mass-rebuild: Fix tty hijacking vulnerability by using su. + (Once su's related bug #628843 is fixed.) Thanks, Ludwig Nussel. + (CVE-2011-1408) + * po: Make po4a warn, not error on a malformed document. (intrigeri) + + -- Joey Hess Wed, 08 Jun 2011 17:34:56 -0400 + +ikiwiki (3.20100815.7) stable-security; urgency=high + + * meta: Security fix; don't allow alternative stylesheets to be added on + pages where the htmlscrubber is enabled. CVE-2011-1401 + + -- Joey Hess Mon, 28 Mar 2011 12:35:13 -0400 + +ikiwiki (3.20100815.6) testing; urgency=low + + * comments: Fix commenting, broken by security fix. + + -- Joey Hess Mon, 24 Jan 2011 16:56:05 -0400 + +ikiwiki (3.20100815.5) testing; urgency=low + + * comments: Fix XSS security hole due to missing validation of page name. + CVE-2011-0428 (Thanks, Dave B.) + + -- Joey Hess Sat, 22 Jan 2011 11:02:59 -0400 + +ikiwiki (3.20100815.4) testing; urgency=low + + * meta: Fix calling of htmlscrubber to pass the page parameter. + The change of the htmlscrubber to look at page rather than destpage + caused htmlscrubber_skip to not work for meta directives. + + -- Joey Hess Mon, 29 Nov 2010 14:44:13 -0400 + +ikiwiki (3.20100815.2) testing; urgency=low + + * Bugfix-only cherry-pick release for Debian squeeze. + * Fix htmlscrubber_skip to be matched on the source page, not the page it is + inlined into. Should allow setting to "* and !comment(*)" to scrub + comments, but leave your blog posts unscrubbed, etc. CVE-2010-1673 + * comments: Make postcomment() pagespec work when previewing a comment, + including during moderation. CVE-2010-1673 + * comments: Make comment() pagespec also match comments that are being + posted. CVE-2010-1673 + * openid: Syntax tweak to the javascript code to make it work with MSIE 7 + (and MSIE 8 in compat mode). Thanks to Iain McLaren for reporting + the bug and providing access to debug it. + * blogspam: Fix crash when content contained utf-8. + * external: Disable RPC::XML's "smart" encoding, which sent ints + for strings that contained only a number, fixing a longstanding crash + of the rst plugin. + * websetup: Fix saving of advanced mode changes. + * websetup: Fix defaults of checkboxes in advanced mode. + * Fix test suite failure on other side of date line. + * Set isPermaLink="no" for guids in rss feeds. + * sortnaturally: Added missing registration of checkconfig hook. + + -- Joey Hess Fri, 12 Nov 2010 11:09:39 -0400 + ikiwiki (3.20100815) unstable; urgency=medium * Fix po test suite to not assume ikiwiki's underlay is already installed.