diff options
author | smcv <smcv@web> | 2016-05-09 08:24:35 -0400 |
---|---|---|
committer | admin <admin@branchable.com> | 2016-05-09 08:24:35 -0400 |
commit | a8c96a1418b4a4bb1f16c80d86f3ef2361b6d64b (patch) | |
tree | ef02711e9644381e8b65fb8e0af12362f5f47917 /doc | |
parent | 176ff2fb5c20d3eaf9322be82e0511c62daac148 (diff) | |
download | ikiwiki-a8c96a1418b4a4bb1f16c80d86f3ef2361b6d64b.tar ikiwiki-a8c96a1418b4a4bb1f16c80d86f3ef2361b6d64b.tar.gz |
mention that the CVE-2016-4561 fix was backported
Diffstat (limited to 'doc')
-rw-r--r-- | doc/security.mdwn | 9 |
1 files changed, 7 insertions, 2 deletions
diff --git a/doc/security.mdwn b/doc/security.mdwn index 594b72126..055e1d006 100644 --- a/doc/security.mdwn +++ b/doc/security.mdwn @@ -514,12 +514,17 @@ CGI error messages did not escape HTML meta-characters, potentially allowing an attacker to carry out cross-site scripting by directing a user to a URL that would result in a crafted ikiwiki error message. This was discovered on 4 May by the ikiwiki developers, and the fixed version -3.20160506 was released on 6 May. An upgrade is recommended for sites using +3.20160506 was released on 6 May. The same fixes were backported to Debian +8 "jessie" in version 3.20141016.3. A backport to Debian 7 "wheezy" is +in progress. + +An upgrade is recommended for sites using the CGI. ([[!cve CVE-2016-4561]], OVE-20160505-0012) ## ImageMagick CVE-2016–3714 ("ImageTragick") -ikiwiki 3.20160506 attempts to mitigate [[!cve CVE-2016-3714]] and any +ikiwiki 3.20160506 and 3.20141016.3 attempt to mitigate +[[!cve CVE-2016-3714]], and any future ImageMagick vulnerabilities that resemble it, by restricting the image formats that the [[ikiwiki/directive/img]] directive is willing to resize. An upgrade is recommended for sites where an untrusted user is |