WARNING: This server is unstable and will be retired in the next days. If you want to keep this forum available, please request immediately a migration on the Nabble Support forum. Forums that don't receive any migration request will be deleted forever.

CGI:IRC 0.5.10 released to fix XSS issue (CVE-2011-0050)

View: New views
1 Messages — Rating Filter:   Alert me  

CGI:IRC 0.5.10 released to fix XSS issue (CVE-2011-0050)

by David Leadbeater :: Rate this Message:

| View Threaded | Show Only this Message

After ~5 years without a release 0.5.10 is now available. This is actually just 0.5.9 with one security fix:

  CVE-2011-0050: XSS in R param in nonjs interface
   
Thanks to Michael Brooks (Sitewatch) for discovering this.

David
------------------------------------------------------------------------------
The ultimate all-in-one performance toolkit: Intel(R) Parallel Studio XE:
Pinpoint memory and threading errors before they happen.
Find and fix more than 250 security defects in the development cycle.
Locate bottlenecks in serial and parallel code that limit performance.
http://p.sf.net/sfu/intel-dev2devfeb
_______________________________________________
cgiirc-general mailing list
cgiirc-general@...
https://lists.sourceforge.net/lists/listinfo/cgiirc-general