X-Git-Url: https://vcs.fsf.org/?p=squirrelmail.git;a=blobdiff_plain;f=doc%2FChangeLog;h=40153a50c2b38206ccf443db2ba672216aa4ba29;hp=f2067c8e44eebf7a61b9914f6a103727dd4907f7;hb=2f617223e0e2742d2d9377aadedd3737b3256430;hpb=117aa0c5efb1d91611d4071ed70f6342be6e8eda;ds=sidebyside diff --git a/doc/ChangeLog b/doc/ChangeLog index f2067c8e..40153a50 100644 --- a/doc/ChangeLog +++ b/doc/ChangeLog @@ -4,6 +4,8 @@ Version 1.5.2 - SVN ------------------- + - Fixed system lock-ups caused by a combination of certain rare, malformed + message headers and buggy versions of PHP mbstring (#3053349, $2987016). - Fix broken set_url_var function in functions/html.php (#1729814). - Fix incorrect detection of auth mechanisms in conf.pl (#1727033). - The search expression in the LDAP backend of the Addressbook is now @@ -348,6 +350,25 @@ Version 1.5.2 - SVN - Fixed issues caused by use of PostgreSQL keyword "user" in SquirrelMail's default preferences database schema (#2943483). - Fixed attachment filename decoding problems (#2994865). + - Now allow multiple plugins to handle (add links for) a single + attachment MIME type. + - Fixed sqauth_read_password() for plugins on the login_verified hook. + - Forced addition of a file suffix to attachments that lack a filename + (helps forwarded messages avoid spam filters) (Thanks to Petr + Kletecka) (#3139004). + - Added smtp_authenticate hook (Thanks to Emmanuel Dreyfus). + - Allow administrators to configure subfolders of user INBOXes to be + treated as special folders by adding $subfolders_of_inbox_are_special + to config_local.php. + - Added clickjacking protection (thanks to Asbjorn Thorsen and Geir Hansen + for bringing this to our attention). [CVE-2010-4554] + - Fixed XSS holes in generic options inputs, XSS hole in the SquirrelSpell + plugin, and added anti-CSRF protection to the empty trash feature (thanks + to Nicholas Carlini for finding all these issues). + [CVE-2011-2752, CVE-2011-2753, CVE-2010-4555] + - Fixed XSS problem with unsanitized style tags in messages. [CVE-2011-2023] + - Always ensure that the Reply-To header is a full email address in + outgoing messages Version 1.5.1 (branched on 2006-02-12) --------------------------------------