diff CHANGES.txt @ 5726:e199d0ae4a25

issue2551033: prevent reverse engineering hidden data by using etags as an oracle to identify when the right data has been guessed. Identified by Joseph Myers who also suggested remediation methods. Implemented John Rouillard.
author John Rouillard <rouilj@ieee.org>
date Thu, 23 May 2019 18:56:57 -0400
parents 6923225fd781
children 943e61bc26d5
line wrap: on
line diff
--- a/CHANGES.txt	Wed May 22 20:56:59 2019 -0400
+++ b/CHANGES.txt	Thu May 23 18:56:57 2019 -0400
@@ -128,6 +128,9 @@
   template. Replace with frame macro. (Cédric Krier)
 - handle UnicodeDecodeError in file class when file contents are
   not text (e.g. jpg). (John Rouillard)
+- issue2551033: prevent reverse engineering hidden data by using etags
+  as an oracle to identify when the right data has been
+  guessed. (Joseph Myers, John Rouillard)
 
 2018-07-13 1.6.0
 

Roundup Issue Tracker: http://roundup-tracker.org/