[Top][All Lists]
[Date Prev][Date Next][Thread Prev][Thread Next][Date Index][Thread Index]
[Erbot-cvs] Changes to erbot/ChangeLog
From: |
Michael W . Olson |
Subject: |
[Erbot-cvs] Changes to erbot/ChangeLog |
Date: |
Wed, 09 Nov 2005 23:32:48 -0500 |
Index: erbot/ChangeLog
diff -u erbot/ChangeLog:1.27 erbot/ChangeLog:1.28
--- erbot/ChangeLog:1.27 Wed Nov 9 01:19:45 2005
+++ erbot/ChangeLog Thu Nov 10 04:32:47 2005
@@ -1,3 +1,10 @@
+2005-11-09 Michael Olson <address@hidden>
+
+ * erbot.el (erbot-reply): Make erbot-safep check each line of the
+ split reply. Split the string on both \n and \r. Together, this
+ fixes an exploit in user-defined functions, which involved
+ returning a string like "^Mquit".
+
2005-11-08 Michael Olson <address@hidden>
* erblisp.el (erblisp-max-list-length): New option that determines
@@ -20,7 +27,7 @@
2005-10-05 D Goel <address@hidden>
* erbot.el (erbot-join-servers): `erc-compute-port' seems to be
- undefined for my older ERC (4.0 $Revision: 1.27 $). So, I
+ undefined for my older ERC (4.0 $Revision: 1.28 $). So, I
reverted to old behavior when it is undefined. Did I do it right?
2005-10-05 Michael Olson <address@hidden>