diff options
author | Simon McVittie <smcv@debian.org> | 2016-05-06 07:49:45 +0100 |
---|---|---|
committer | Simon McVittie <smcv@debian.org> | 2016-05-06 07:49:45 +0100 |
commit | dea96e51136ee44971f3e3dafad67f8a5e111c50 (patch) | |
tree | 6addbb7ffb4e903c4906bc3a9c1a898f120719e9 /debian | |
parent | 21b9b9e306c36616f251b727d2e87a5d8538e5e4 (diff) | |
download | ikiwiki-dea96e51136ee44971f3e3dafad67f8a5e111c50.tar ikiwiki-dea96e51136ee44971f3e3dafad67f8a5e111c50.tar.gz |
Document the security fixes in this release
Diffstat (limited to 'debian')
-rw-r--r-- | debian/NEWS | 24 |
1 files changed, 24 insertions, 0 deletions
diff --git a/debian/NEWS b/debian/NEWS index b2753c638..66b2b4299 100644 --- a/debian/NEWS +++ b/debian/NEWS @@ -1,3 +1,27 @@ +ikiwiki (3.20160506) UNRELEASED; urgency=medium + + To mitigate CVE-2016-3714 and similar ImageMagick security vulnerabilities, + the [[!img]] directive is now restricted to these common web formats by + default: + + * JPEG (.jpg, .jpeg) + * PNG (.png) + * GIF (.gif) + * SVG (.svg) + + (In particular, by default resizing PDF files is no longer allowed.) + + Additionally, resized SVG files are displayed in the browser as SVG + instead of being converted to PNG. + + If all users who can attach images are fully trusted, this restriction + can be removed with the new img_allowed_formats setup option. + See <https://ikiwiki.info/ikiwiki/directive/img/> + or <file:///usr/share/doc/ikiwiki/html/ikiwiki/directive/img.html> for + more details. + + -- Simon McVittie <smcv@debian.org> Fri, 06 May 2016 07:07:29 +0100 + ikiwiki (3.20150610) unstable; urgency=low The new "emailauth" plugin allows users to authenticate using an email |