[Top][All Lists]

[Date Prev][Date Next][Thread Prev][Thread Next][Date Index][Thread Index]

LYNX-DEV update (Re: CERT VU#5135)

From: Foteos Macrides
Subject: LYNX-DEV update (Re: CERT VU#5135)
Date: Tue, 24 Jun 1997 17:13:35 -0500 (EST)

        An update of is available in:

* Mods in LYDownload.c to check whether the File= field in a LYNXDOWNLOAD
  URL has the value that was inserted into the URL via the most recent
  download options menu.  This prevents spoofing with arbitary LYNXDOWNLOAD
  URLs entered via the 'g'oto or ECGOTO commands, or ACTIVATE-ed in a file
  other than the most recent download options menu which was created by
  Lynx internally. - FM
* Mods in LYMainLoop.c to ignore LYNXCOOKIE, LYNXDIRED, LYNXDOWNLOAD, and
  LYNXPRINT URLs if entered via a 'g'oto or ECGOTO command, and to issue
  a statusline message explaining that the special URL is not allowed as a
  goto.  This is just for informational purposes, and the above anti-spoof
  mod is not dependent on it. - FM


 Foteos Macrides            Worcester Foundation for Biomedical Research
 address@hidden         222 Maple Avenue, Shrewsbury, MA 01545
; To UNSUBSCRIBE:  Send a mail message to address@hidden
;                  with "unsubscribe lynx-dev" (without the
;                  quotation marks) on a line by itself.

reply via email to

[Prev in Thread] Current Thread [Next in Thread]