X-Git-Url: https://vcs.fsf.org/?a=blobdiff_plain;f=ChangeLog;h=27eb5a5cadc870c7ce9fc36be9aa78274d9d7436;hb=546d6debcb2172f29718cf6c02a6f0fcce83a3c1;hp=acf83c48edf6b92cfe8c526a04c5867a8b72c5ec;hpb=ee951d3aae14fcd054f9771f48dd5f518f351a0c;p=squirrelmail.git diff --git a/ChangeLog b/ChangeLog index acf83c48..27eb5a5c 100644 --- a/ChangeLog +++ b/ChangeLog @@ -188,6 +188,16 @@ Version 1.5.2 - SVN HTML addressbook, and allow returning from an empty address book (#1673056). - Do not special case the 'None' folder. - Fixes for filters issues (#1634735). + - session_id reporting session id when no active session (#1685031). + - Added sq_change_text_domain() for plugins to use when switching text + domains. If plugins use this function, it fixes #1434043. + - Add dynamic textarea sizing slider control to compose screen (default_advanced + skin) + - Security: fixes for the HTML filter to counter further XSS exploits: + HTML attachments containing 'data:' URLs, Internet Explorer-specifc + charset conversion exploits, and request forgery through included + images. Thanks to Mikhail Markin, Tomas Kuliavas and Michael Jordon + for reporting these issues. [CVE-2007-1262] Version 1.5.1 (branched on 2006-02-12) --------------------------------------