[dokuwiki] Re: Security Tracker "bug", Request Patch

  • From: Burton Rosenberg <burt@xxxxxxxxxxxx>
  • To: dokuwiki@xxxxxxxxxxxxx
  • Date: Fri, 2 Jun 2006 22:35:27 -0400

So in this case, 2006-03-09 is the current release, and there is no patches. If this bug were critical, you would post a 2006-03-09-A along w/
diffs from the previous release?


Do you know off hand how the FreeBSD port maintainer deals w/ this? Do you alert, or are they individually attentive?

-burt


On Jun 2, 2006, at 3:33 PM, Andreas Gohr wrote:

burt wrote:
Thanks. I think this is a good plan. However, I am concerned that I don't end up running beta code, but keeping sync w/ the dev tree.

I don't recommend running devel releases on production servers. Instead you should just fix security problems. Critical bugs are always announced at the freshmeat announcement list together with a link to a description on how to manually fix the problem. Usually a fixed release (version number just gets a letter appended) is provided for download as well.


However in this case the problem is considered non-critical as it is only exploitable by admin users. Normal users could just hack them self ;-)

See
http://bugs.splitbrain.org/?do=details&id=820
on how you could fix it your self.

Andi

--
DokuWiki mailing list - more info at
http://wiki.splitbrain.org/wiki:mailinglist

-- DokuWiki mailing list - more info at http://wiki.splitbrain.org/wiki:mailinglist

Other related posts: