From 29ab0855f044ef2fe9c295b72abefcb37f0861a5 Mon Sep 17 00:00:00 2001 From: Daniel Friesel Date: Wed, 9 Feb 2011 20:14:54 +0100 Subject: Release v1.11.2 (unlikely issue, but a release never hurts) --- ChangeLog | 9 +++++++++ 1 file changed, 9 insertions(+) diff --git a/ChangeLog b/ChangeLog index 98cee36..6359db8 100644 --- a/ChangeLog +++ b/ChangeLog @@ -1,3 +1,12 @@ +Wed, 09 Feb 2011 20:11:26 +0100 Daniel Friesel + +* Release v1.11.2 + * Use wget --no-clobber to prevent TOCTTOU-based hole allowing a + well-informed attacker to rewrite arbitrary user files with images. + The attacker needs to know feh's PID and the URL the user gave it. + It is still possible for an attacker to _create_ arbitrary files via the + same hole. + Wed, 26 Jan 2011 21:07:19 +0100 * Release v1.11.1 -- cgit v1.2.3