diff options
Diffstat (limited to 'doc')
-rw-r--r-- | doc/ikiwikiusers.mdwn | 1 | ||||
-rw-r--r-- | doc/security.mdwn | 17 |
2 files changed, 10 insertions, 8 deletions
diff --git a/doc/ikiwikiusers.mdwn b/doc/ikiwikiusers.mdwn index cf3498d44..8d52059a9 100644 --- a/doc/ikiwikiusers.mdwn +++ b/doc/ikiwikiusers.mdwn @@ -16,6 +16,7 @@ Sites that are using ikiwiki include: * Kelly Clowers' [personal website](http://www.clowersnet.net/) * Anna's [nature features](http://kitenet.net/~anna/nature-feature/) * [Planet Debian upstream](http://updo.kitenet.net/) +* Roland Mas's [blog](http://roland.entierement.nu/categories/geek-en.html) Please feel free to add your own ikiwiki site! diff --git a/doc/security.mdwn b/doc/security.mdwn index b3b5b6f3e..65ebfd7b2 100644 --- a/doc/security.mdwn +++ b/doc/security.mdwn @@ -18,14 +18,6 @@ Anyone with direct commit access can forge "web commit from foo" and make it appear on [[RecentChanges]] like foo committed. One way to avoid this would be to limit web commits to those done by a certian user. -## XML::Parser - -XML::Parser is used by the aggregation plugin, and has some security holes -that are still open in Debian unstable as of this writing. #378411 does not -seem to affect our use, since the data is not encoded as utf-8 at that -point. #378412 could affect us, although it doesn't seem very exploitable. -It has a simple fix, which should be NMUed or something.. - ## other stuff to look at I need to audit the git backend a bit, and have been meaning to @@ -246,3 +238,12 @@ have come just before yours, by forging svn log output. This was guarded against by using svn log --xml. ikiwiki escapes any html in svn commit logs to prevent other mischief. + +## XML::Parser + +XML::Parser is used by the aggregation plugin, and has some security holes. +#[378411](http://bugs.debian.org/378411) does not +seem to affect our use, since the data is not encoded as utf-8 at that +point. #[378412](http://bugs.debian.org/378412) could affect us, although it +doesn't seem very exploitable. It has a simple fix, and has been fixed in +Debian unstable. |