--- - branch: MAIN date: Sun Sep 13 01:15:11 UTC 2009 files: - new: '1.23' old: '1.22' path: pkgsrc/www/geeklog/Makefile pathrev: pkgsrc/www/geeklog/Makefile@1.23 type: modified - new: '1.10' old: '1.9' path: pkgsrc/www/geeklog/PLIST pathrev: pkgsrc/www/geeklog/PLIST@1.10 type: modified - new: '1.10' old: '1.9' path: pkgsrc/www/geeklog/distinfo pathrev: pkgsrc/www/geeklog/distinfo@1.10 type: modified - new: '1.4' old: '1.3' path: pkgsrc/www/geeklog/patches/patch-aa pathrev: pkgsrc/www/geeklog/patches/patch-aa@1.4 type: modified - new: '1.2' old: '1.1' path: pkgsrc/www/geeklog/patches/patch-aj pathrev: pkgsrc/www/geeklog/patches/patch-aj@1.2 type: modified - new: '1.1' old: '0' path: pkgsrc/www/geeklog/patches/patch-ak pathrev: pkgsrc/www/geeklog/patches/patch-ak@1.1 type: added - new: '1.1' old: '0' path: pkgsrc/www/geeklog/patches/patch-al pathrev: pkgsrc/www/geeklog/patches/patch-al@1.1 type: added - new: '1.1' old: '0' path: pkgsrc/www/geeklog/patches/patch-ba pathrev: pkgsrc/www/geeklog/patches/patch-ba@1.1 type: added - new: '1.1' old: '0' path: pkgsrc/www/geeklog/patches/patch-bb pathrev: pkgsrc/www/geeklog/patches/patch-bb@1.1 type: added - new: '1.1' old: '0' path: pkgsrc/www/geeklog/patches/patch-bc pathrev: pkgsrc/www/geeklog/patches/patch-bc@1.1 type: added - new: '1.1' old: '0' path: pkgsrc/www/geeklog/patches/patch-bd pathrev: pkgsrc/www/geeklog/patches/patch-bd@1.1 type: added id: 20090913T011511Z.413489e333b0625dafe0eb3ebff7d3af5253c046 log: | Update Geeklog 1.5.2sr5 by adding patches since 1.5.2sr5 isn't provided as full release. And add updated fckeditor for Geeklog. These updates should fix known security problems, Secunia SA36372. Jul 30, 2009 (1.5.2sr5) ------------ This release addresses the following security issues: - Gerendi Sandor Attila reported an XSS in the forms to email a user and to email a story to a friend. - The "Mail Story to a Friend" function didn't check story permissions, so that it was possible to email a story even if you didn't have the permissions to view it on the site. module: pkgsrc subject: 'CVS commit: pkgsrc/www/geeklog' unixtime: '1252804511' user: taca