From f0cb1f93318e64f8205425923b6597a7a8e876b8 Mon Sep 17 00:00:00 2001 From: kink Date: Mon, 4 Dec 2006 08:46:31 +0000 Subject: [PATCH] add security fixes to changelog git-svn-id: https://svn.code.sf.net/p/squirrelmail/code/trunk/squirrelmail@11987 7612ce4b-ef26-0410-bec9-ea0150e637f0 --- ChangeLog | 3 +++ 1 file changed, 3 insertions(+) diff --git a/ChangeLog b/ChangeLog index 070071e4..7da195a1 100644 --- a/ChangeLog +++ b/ChangeLog @@ -163,6 +163,9 @@ Version 1.5.2 - CVS and mailto functionality [CVE-2006-6142]. - Security: work around an issue in Internet Explorer that would guess the mime type of a file based on contents, not Content-Type header. + - Security: Multiple IE cross site scripting issues related to the + generous parsing of the words 'expression' and 'url' by IE. + - Security: Removing @import when sanitizing html mail. Version 1.5.1 (branched on 2006-02-12) -------------------------------------- -- 2.25.1