diff options
Diffstat (limited to 'ChangeLog')
-rw-r--r-- | ChangeLog | 7 |
1 files changed, 7 insertions, 0 deletions
@@ -1,3 +1,10 @@ +Sun Aug 15 19:59:58 2010 Yuki Sonoda (Yugui) <yugui@yugui.jp> + + * lib/webrick/httpresponse.rb (WEBrick::HTTPResponse#set_error): + Fix for possible cross-site scripting (CVE-2010-0541). + Found by Apple, reported by Hideki Yamane. + Patch by Hirokazu Nishio <nishio.hirokazu AT gmail.com>. + Fri Jul 2 19:07:09 2010 Yuki Sonoda (Yugui) <yugui@yugui.jp> * io.c (argf_inplace_mode_set): prohibits an assignment |