X-Git-Url: https://vcs.fsf.org/?p=squirrelmail.git;a=blobdiff_plain;f=doc%2FChangeLog;h=40153a50c2b38206ccf443db2ba672216aa4ba29;hp=7a6ca13e0ab1007cf772c7be96ac5b8d0e7acda2;hb=2f617223e0e2742d2d9377aadedd3737b3256430;hpb=2f3be4069177a9a93c490f94c5b665268c61e2e8 diff --git a/doc/ChangeLog b/doc/ChangeLog index 7a6ca13e..40153a50 100644 --- a/doc/ChangeLog +++ b/doc/ChangeLog @@ -350,6 +350,25 @@ Version 1.5.2 - SVN - Fixed issues caused by use of PostgreSQL keyword "user" in SquirrelMail's default preferences database schema (#2943483). - Fixed attachment filename decoding problems (#2994865). + - Now allow multiple plugins to handle (add links for) a single + attachment MIME type. + - Fixed sqauth_read_password() for plugins on the login_verified hook. + - Forced addition of a file suffix to attachments that lack a filename + (helps forwarded messages avoid spam filters) (Thanks to Petr + Kletecka) (#3139004). + - Added smtp_authenticate hook (Thanks to Emmanuel Dreyfus). + - Allow administrators to configure subfolders of user INBOXes to be + treated as special folders by adding $subfolders_of_inbox_are_special + to config_local.php. + - Added clickjacking protection (thanks to Asbjorn Thorsen and Geir Hansen + for bringing this to our attention). [CVE-2010-4554] + - Fixed XSS holes in generic options inputs, XSS hole in the SquirrelSpell + plugin, and added anti-CSRF protection to the empty trash feature (thanks + to Nicholas Carlini for finding all these issues). + [CVE-2011-2752, CVE-2011-2753, CVE-2010-4555] + - Fixed XSS problem with unsanitized style tags in messages. [CVE-2011-2023] + - Always ensure that the Reply-To header is a full email address in + outgoing messages Version 1.5.1 (branched on 2006-02-12) --------------------------------------