Path to this page:
Subject: CVS commit: pkgsrc/www/trac
From: Thomas Klausner
Date: 2007-03-10 21:55:34
Message id: 20070310205534.6CD3B2150A@cvs.netbsd.org
Log Message:
Update to 0.10.3.1:
Trac 0.10.3.1 (March 8, 2007)
http://svn.edgewall.org/repos/trac/tags/trac-0.10.3.1
Trac 0.10.3.1 is a security release:
* Always send "Content-Disposition: attachment" headers where potentially
unsafe (user provided) content is available for download. This behaviour
can be altered using the "render_unsafe_content" option in the
"attachment" and "browser" sections of trac.ini.
* Fixed XSS vulnerability in "download wiki page as text" in \
combination with
Microsoft IE. Reported by Yoshinori Oota, Business Architects Inc.
Files: