X-Git-Url: http://sjero.net/git/?p=wget;a=blobdiff_plain;f=NEWS;h=488c9a50e869eb1b4f25859469199cb98363a5ba;hp=559558e741397b0e4f01bf901f3fe792aeda7553;hb=1e5a791a224db14719e19e33ffa007ab8d8e8adf;hpb=9dadbf6fe9577a6a6b7e7bab4e4b782fc1a6f86c diff --git a/NEWS b/NEWS index 559558e7..488c9a50 100644 --- a/NEWS +++ b/NEWS @@ -10,6 +10,11 @@ Please send GNU Wget bug reports to . ** Mailing list MOVED to bug-wget@gnu.org +** SECURITY FIX: It had been possible to trick Wget into accepting +SSL certificates that don't match the host name, through the trick of +embedding NUL characters into the certs' common name. Fixed by Joao +Ferreira . + ** Added support for CSS. This includes: - Parsing links from CSS files, and from CSS content found in HTML style tags and attributes. @@ -22,11 +27,13 @@ Please send GNU Wget bug reports to . . ** Added support for Internationalized Resource Identifiers (IRIs, RFC -3987). When support is enabled (default), links with non-ASCII bytes -are translated from their source encoding to UTF-8 before percent-encoding. +3987). When support is enabled (requires libidn and libiconv), links +with non-ASCII bytes are translated from their source encoding to UTF-8 +before percent-encoding. IRI support was added by Saint Xavier +, as his project for the Google Summer of Code. - IRI support was added by Saint Xavier , as his - project for the Google Summer of Code. +** Wget now provides more sensible exit status codes when downloads +don't proceed as expected (see the manual). ** --default-page option (and associated wgetrc command) added to support alternative default names for index.html. @@ -42,7 +49,8 @@ information on how it was built, and the set of configure-time options that were selected. ** --html-extension has been renamed to --adjust-extension, to reflect -the fact that it now also applies to CSS content.. +the fact that it now also applies to CSS content. --html-extension is +still acceptable, but is now deprecated. ** An "ascii" specifier is now accepted by --restrict-file-names, which forces the percent-encoding of all non-ASCII bytes