summaryrefslogtreecommitdiff
path: root/ChangeLog
diff options
context:
space:
mode:
Diffstat (limited to 'ChangeLog')
-rw-r--r--ChangeLog7
1 files changed, 7 insertions, 0 deletions
diff --git a/ChangeLog b/ChangeLog
index 4179e81b..4d8ec23c 100644
--- a/ChangeLog
+++ b/ChangeLog
@@ -1,3 +1,10 @@
+2007-11-22 Eric Blake <ebb9@byu.net>
+
+ Security fix: avoid arbitrary code execution with 'm4 -F'.
+ * src/freeze.c (produce_frozen_state): Never pass raw file name as
+ printf format.
+ * NEWS: Document this fix.
+
2007-11-21 Eric Blake <ebb9@byu.net>
Consistently report macro name first in messages.