From fe0230678fed3ffba9741724de62952c582ffe6b Mon Sep 17 00:00:00 2001 From: Daniel Friesel Date: Fri, 25 Jun 2010 13:49:41 +0200 Subject: ChangeLog: It's not _remote_ code execution --- ChangeLog | 2 +- 1 file changed, 1 insertion(+), 1 deletion(-) diff --git a/ChangeLog b/ChangeLog index 0599038..d73c931 100644 --- a/ChangeLog +++ b/ChangeLog @@ -12,7 +12,7 @@ git HEAD to handling of uninitialised memory. Since I consider this a rarely useful action, the feature has been disabled for thumbnail mode. * Remove -G/--wget-timestamp option. It was probably not working - correctly, plus it contained a remote code execution hole when used with + correctly, plus it contained a code execution hole when used with malicious URLs containing shell metacharacters (but only if those URLs led to a valid file) * Don't add ?randomnumber to URLs, it confuses some servers and is -- cgit v1.2.3