From: Wim K. <wi...@us...> - 2002-04-25 16:17:14
|
Update of /cvsroot/acmemail/acmemail In directory usw-pr-cvs1:/tmp/cvs-serv21725 Modified Files: ChangeLog Log Message: Updating the ChangeLog for the release Index: ChangeLog =================================================================== RCS file: /cvsroot/acmemail/acmemail/ChangeLog,v retrieving revision 1.18 retrieving revision 1.19 diff -u -r1.18 -r1.19 --- ChangeLog 23 Apr 2002 00:56:49 -0000 1.18 +++ ChangeLog 25 Apr 2002 16:17:04 -0000 1.19 @@ -1,17 +1,14 @@ -Since 2.2.3: +Thu Apr 25 09:20:00 PDT 2002 Wim Kerkhoff <wi...@ny...> + * Released as 2.2.4 * Switch to the Date::Format and Date::Parse, which apparently come included on modern Linux distributions. Patch from Wayne Davison * Switch from MD5 to Digest::MD5. Patch from Wayne Davison - * Fix for BSD/OS 4.2. Apparently, on BSD/OS 4.2 mkdir will not - create a directory when the specified path has a trailing "/", such as - "mkdir foo/bar/". Works fine with "mkdir foo/bar". Same problem probably - occurs on other BSD4.4 derivates such derivates such as Sun OS and - Solaris. Patch from A.Lalev + * Fix for mkdir problem BSD/OS 4.2. Patch from A.Lalev * Fixing a nasty CSS vulnerability. Basically it was possible for somebody to run JavaScript code like this: http://your .domain/cgi-bin/acmemail.cgi?aredir=javascript:alert(document.cookie). This patches forces aredir to be a http:// or https:// link. - Found by Nick Cleaton, fixed by Wim Kerkhoff + Found by Nick Cleaton * Add RFC822 compliant Date header to outgoing messages * Handle the case where there is no Date header, so that the full version of the epoch is not used |