Commit 1cc0b16a authored by Per Cederqvist's avatar Per Cederqvist
Browse files

Require that the user is logged in before allowing him to do

get-last-text, find-next-text-no or find-previous-text-no.  This fixes
a denial-of-service attack reported by Calle Dybedahl.
parent de65de64
2003-05-09 Per Cederqvist <ceder@ingate.com>
Require that the user is logged in before allowing him to do
get-last-text, find-next-text-no or find-previous-text-no. This
fixes a denial-of-service attack reported by Calle Dybedahl.
* src/server/text.c (get_last_text): Require the user to be logged
in.
(find_next_text_no): Ditto.
(find_previous_text_no): Ditto.
* doc/Protocol-A.texi (get-last-text): This request now requires
that the user is logged in.
(find-next-text-no): Ditto.
(find-previous-text-no): Ditto.
2003-03-23 Per Cederqvist <ceder@ceder.dyndns.org>
Don't copy zero-length arrays. (Bug 1005).
......
Markdown is supported
0% or .
You are about to add 0 people to the discussion. Proceed with caution.
Finish editing this message first!
Please register or to comment