I received notice of a security flaw from Dan Libby, details of which I
attach to this mail.
I have put fixes for this flaw into the CVS repository. In so doing I
created a branch called "stable1_0", for doing releases off of the
stable code.
Hence the new release has version 1.01, and differs only from 1.0 in the
security fix and version number.
Development still continues on the HEAD branch as normal. I also
checked the fixes into HEAD.
As soon as the new releases show up on SourceForge I will notify people
that they need to update as a matter of urgency.
-- Edd
|