From c10bf4d051c97939b30a1616c0499310057d07da Mon Sep 17 00:00:00 2001 From: Damien Miller Date: Sun, 20 Apr 2014 12:58:04 +1000 Subject: - djm@cvs.openbsd.org 2014/03/03 22:22:30 [session.c] ignore enviornment variables with embedded '=' or '\0' characters; spotted by Jann Horn; ok deraadt@ Id sync only - portable already has this. --- ChangeLog | 8 ++++++++ 1 file changed, 8 insertions(+) (limited to 'ChangeLog') diff --git a/ChangeLog b/ChangeLog index 9cbc1cef1..97c253339 100644 --- a/ChangeLog +++ b/ChangeLog @@ -1,3 +1,11 @@ +20140420 + - OpenBSD CVS Sync + - djm@cvs.openbsd.org 2014/03/03 22:22:30 + [session.c] + ignore enviornment variables with embedded '=' or '\0' characters; + spotted by Jann Horn; ok deraadt@ + Id sync only - portable already has this. + 20140401 - (djm) On platforms that support it, use prctl() to prevent sftp-server from accessing /proc/self/{mem,maps}; patch from jann AT thejh.net -- cgit v1.2.3