erbot-cvs
[Top][All Lists]
Advanced

[Date Prev][Date Next][Thread Prev][Thread Next][Date Index][Thread Index]

[Erbot-cvs] Changes to erbot/ChangeLog


From: Michael W . Olson
Subject: [Erbot-cvs] Changes to erbot/ChangeLog
Date: Wed, 09 Nov 2005 23:32:48 -0500

Index: erbot/ChangeLog
diff -u erbot/ChangeLog:1.27 erbot/ChangeLog:1.28
--- erbot/ChangeLog:1.27        Wed Nov  9 01:19:45 2005
+++ erbot/ChangeLog     Thu Nov 10 04:32:47 2005
@@ -1,3 +1,10 @@
+2005-11-09  Michael Olson  <address@hidden>
+
+       * erbot.el (erbot-reply): Make erbot-safep check each line of the
+       split reply.  Split the string on both \n and \r.  Together, this
+       fixes an exploit in user-defined functions, which involved
+       returning a string like "^Mquit".
+
 2005-11-08  Michael Olson  <address@hidden>
 
        * erblisp.el (erblisp-max-list-length): New option that determines
@@ -20,7 +27,7 @@
 2005-10-05  D Goel  <address@hidden>
 
        * erbot.el (erbot-join-servers): `erc-compute-port' seems to be
-       undefined for my older ERC (4.0 $Revision: 1.27 $).  So, I
+       undefined for my older ERC (4.0 $Revision: 1.28 $).  So, I
        reverted to old behavior when it is undefined.  Did I do it right?
 
 2005-10-05  Michael Olson  <address@hidden>




reply via email to

[Prev in Thread] Current Thread [Next in Thread]