X-Git-Url: http://git.marmaro.de/?p=mmh;a=blobdiff_plain;f=ChangeLog;h=e44eda5dea099e6254296f54dc069123fd88c0d4;hp=725c4b972b5fc50115853be77db2779214b2135f;hb=8146bc09fc2e8ad69520ba998be51fb02cbf069c;hpb=0d1c5f533f3a6cd1c7f038f59585378f53b666c2 diff --git a/ChangeLog b/ChangeLog index 725c4b9..e44eda5 100644 --- a/ChangeLog +++ b/ChangeLog @@ -1,4 +1,29 @@ -Thu Feb 03 17:22:48 2000 Dan Harkless +Sun Feb 20 12:17:15 2000 Ruud de Rooij + + * Fix security hole in mhshowsbr.c which allowed untrusted shell + code to be executed. + * Released nmh 1.0.3. + +Thu Feb 10 10:54:36 2000 Dan Harkless + + * Oops. %-escapes on mhstore lines in mhn.defaults.sh should not + be surrounded by single quotes, as a shell is not spawned when + just saving files, and the filenames will end up with literal + quotes embedded in them. + +Fri Feb 04 12:29:12 2000 Dan Harkless + + * Whoever originally added the -help switch to all the commands + got too cute and had the option itself print out as "-(help)" in + the -help output. I guess the idea was to make reference to the + fact that clearly you know about the -help option since you're + currently looking at its output. I think it's a bad idea to + overload the meaning of the parentheses, however -- they're + supposed to indicate what abbreviated prefix of the switch you're + allowed to specify. It doesn't make sense to show that you're + allowed to "abbreviate" the switch to its entire length. + +Thu Feb 03 17:52:01 2000 Dan Harkless * Applied wesley.craig@umich.edu's KPOP patches. According to him: @@ -12,6 +37,8 @@ Thu Feb 03 17:22:48 2000 Dan Harkless * Modified inc.man and msgchk.man to document Wesley's new -kpop. + * Modified INSTALL and config.h.in to reflect the new -kpop feature. + Fri Jan 28 17:39:24 2000 Dan Harkless * All %-escapes in mhn.defaults that actually expand to something