diff options
author | joey <joey@0fa5a96a-9a0e-0410-b3b2-a0fd24251071> | 2007-03-21 06:05:21 +0000 |
---|---|---|
committer | joey <joey@0fa5a96a-9a0e-0410-b3b2-a0fd24251071> | 2007-03-21 06:05:21 +0000 |
commit | 1c65ca492295e754dfd9986f91b08eb0876d09b9 (patch) | |
tree | f5ef8f767cf58055381e730e88a56f30ffa586b6 /debian/changelog | |
parent | 9bf29d60b2b44c16e9c3aaf1f4ff78a694f3c194 (diff) |
* Fix a few bugs around page titles containing html. The worst of these
is an actual security hole as it allows insertion of html into the title
element of a page, which is not processed by the htmlscrubber.
Diffstat (limited to 'debian/changelog')
-rw-r--r-- | debian/changelog | 7 |
1 files changed, 5 insertions, 2 deletions
diff --git a/debian/changelog b/debian/changelog index 26aaad53b..5934958ce 100644 --- a/debian/changelog +++ b/debian/changelog @@ -1,4 +1,4 @@ -ikiwiki (1.46) UNRELEASED; urgency=low +ikiwiki (1.46) unstable; urgency=low * Fix a bug with inlined create page links, including Discussion links on blog post pages. The links will now create pages relative to the page that @@ -12,8 +12,11 @@ ikiwiki (1.46) UNRELEASED; urgency=low same time, and let the second person resolve the conflict. * Applied a patch from MichaĆ to make the mercurial backend pass --quiet to hg. + * Fix a few bugs around page titles containing html. The worst of these + is an actual security hole as it allows insertion of html into the title + element of a page, which is not processed by the htmlscrubber. - -- Joey Hess <joeyh@debian.org> Sun, 18 Mar 2007 18:22:12 -0400 + -- Joey Hess <joeyh@debian.org> Wed, 21 Mar 2007 01:51:30 -0400 ikiwiki (1.45) unstable; urgency=low |