diff options
author | joey <joey@0fa5a96a-9a0e-0410-b3b2-a0fd24251071> | 2006-08-05 21:15:50 +0000 |
---|---|---|
committer | joey <joey@0fa5a96a-9a0e-0410-b3b2-a0fd24251071> | 2006-08-05 21:15:50 +0000 |
commit | 2ea8fbe2d9691d48b007bd0404dd77ae4bd3c9c7 (patch) | |
tree | c4efd2cb2790ce2b77d8c6dc474e5d1b1c5d2d91 /doc/security.mdwn | |
parent | 7a05087f475e897560c34a614108dae50ba05c62 (diff) | |
download | ikiwiki-2ea8fbe2d9691d48b007bd0404dd77ae4bd3c9c7.tar ikiwiki-2ea8fbe2d9691d48b007bd0404dd77ae4bd3c9c7.tar.gz |
misc changes
Diffstat (limited to 'doc/security.mdwn')
-rw-r--r-- | doc/security.mdwn | 17 |
1 files changed, 9 insertions, 8 deletions
diff --git a/doc/security.mdwn b/doc/security.mdwn index b3b5b6f3e..65ebfd7b2 100644 --- a/doc/security.mdwn +++ b/doc/security.mdwn @@ -18,14 +18,6 @@ Anyone with direct commit access can forge "web commit from foo" and make it appear on [[RecentChanges]] like foo committed. One way to avoid this would be to limit web commits to those done by a certian user. -## XML::Parser - -XML::Parser is used by the aggregation plugin, and has some security holes -that are still open in Debian unstable as of this writing. #378411 does not -seem to affect our use, since the data is not encoded as utf-8 at that -point. #378412 could affect us, although it doesn't seem very exploitable. -It has a simple fix, which should be NMUed or something.. - ## other stuff to look at I need to audit the git backend a bit, and have been meaning to @@ -246,3 +238,12 @@ have come just before yours, by forging svn log output. This was guarded against by using svn log --xml. ikiwiki escapes any html in svn commit logs to prevent other mischief. + +## XML::Parser + +XML::Parser is used by the aggregation plugin, and has some security holes. +#[378411](http://bugs.debian.org/378411) does not +seem to affect our use, since the data is not encoded as utf-8 at that +point. #[378412](http://bugs.debian.org/378412) could affect us, although it +doesn't seem very exploitable. It has a simple fix, and has been fixed in +Debian unstable. |