aboutsummaryrefslogtreecommitdiff
path: root/doc/security.mdwn
diff options
context:
space:
mode:
authorjoey <joey@0fa5a96a-9a0e-0410-b3b2-a0fd24251071>2006-08-05 21:15:50 +0000
committerjoey <joey@0fa5a96a-9a0e-0410-b3b2-a0fd24251071>2006-08-05 21:15:50 +0000
commit2ea8fbe2d9691d48b007bd0404dd77ae4bd3c9c7 (patch)
treec4efd2cb2790ce2b77d8c6dc474e5d1b1c5d2d91 /doc/security.mdwn
parent7a05087f475e897560c34a614108dae50ba05c62 (diff)
downloadikiwiki-2ea8fbe2d9691d48b007bd0404dd77ae4bd3c9c7.tar
ikiwiki-2ea8fbe2d9691d48b007bd0404dd77ae4bd3c9c7.tar.gz
misc changes
Diffstat (limited to 'doc/security.mdwn')
-rw-r--r--doc/security.mdwn17
1 files changed, 9 insertions, 8 deletions
diff --git a/doc/security.mdwn b/doc/security.mdwn
index b3b5b6f3e..65ebfd7b2 100644
--- a/doc/security.mdwn
+++ b/doc/security.mdwn
@@ -18,14 +18,6 @@ Anyone with direct commit access can forge "web commit from foo" and
make it appear on [[RecentChanges]] like foo committed. One way to avoid
this would be to limit web commits to those done by a certian user.
-## XML::Parser
-
-XML::Parser is used by the aggregation plugin, and has some security holes
-that are still open in Debian unstable as of this writing. #378411 does not
-seem to affect our use, since the data is not encoded as utf-8 at that
-point. #378412 could affect us, although it doesn't seem very exploitable.
-It has a simple fix, which should be NMUed or something..
-
## other stuff to look at
I need to audit the git backend a bit, and have been meaning to
@@ -246,3 +238,12 @@ have come just before yours, by forging svn log output. This was
guarded against by using svn log --xml.
ikiwiki escapes any html in svn commit logs to prevent other mischief.
+
+## XML::Parser
+
+XML::Parser is used by the aggregation plugin, and has some security holes.
+#[378411](http://bugs.debian.org/378411) does not
+seem to affect our use, since the data is not encoded as utf-8 at that
+point. #[378412](http://bugs.debian.org/378412) could affect us, although it
+doesn't seem very exploitable. It has a simple fix, and has been fixed in
+Debian unstable.