]> git.vanrenterghem.biz Git - git.ikiwiki.info.git/commitdiff
meta: Security fix; don't allow alternative stylesheets to be added on pages where...
authorJoey Hess <joey@kitenet.net>
Mon, 28 Mar 2011 16:36:07 +0000 (12:36 -0400)
committerJoey Hess <joey@kitenet.net>
Mon, 28 Mar 2011 16:36:07 +0000 (12:36 -0400)
IkiWiki/Plugin/meta.pm
debian/changelog

index 5c1827cc03549c7041029f74ee0a8abf142ba0c1..0e4fcb1dc5357d17e2de3cc7a540165485f6a259 100644 (file)
@@ -136,10 +136,10 @@ sub preprocess (@) { #{{{
                if (! length $stylesheet) {
                        return "[[meta ".gettext("stylesheet not found")."]]";
                }
-               push @{$metaheaders{$page}}, '<link href="'.urlto($stylesheet, $page).
+               push @{$metaheaders{$page}}, scrub('<link href="'.urlto($stylesheet, $page).
                        '" rel="'.encode_entities($rel).
                        '" title="'.encode_entities($title).
-                       "\" type=\"text/css\" />";
+                       "\" type=\"text/css\" />");
        }
        elsif ($key eq 'openid') {
                if (exists $params{server} && safeurl($params{server})) {
index c01b697e367e3c80b1d97b93a595d745f510c0e5..bd030457fbca62fc3b63855111bf679128019db0 100644 (file)
@@ -1,3 +1,10 @@
+ikiwiki (2.53.6) oldstable-security; urgency=low
+
+  * meta: Security fix; don't allow alternative stylesheets to be added on
+    pages where the htmlscrubber is enabled.
+
+ -- Joey Hess <joeyh@debian.org>  Mon, 28 Mar 2011 12:35:13 -0400
+
 ikiwiki (2.53.5) stable-security; urgency=high
 
   * htmlscrubber: Security fix: In data:image/* uris, only allow a few