According to Dan Langille: > On 23 Sep 2001 at 23:51, Geoff Hutchison wrote: > > It is *strongly* recommended that you either patch your version of > > htsearch with the patches enclosed (for both 3.1.x and 3.2.0 beta > > versions) or download the most recent snapshots of 3.1.6 or 3.2.0b4 in the > > snapshots directory given above. Anyone upgrading from a 3.1.x stable > > release will find the process fairly painless and to fix the hole, they > > can simply drop in the new CGI. The databases themselves are not affected. > > The patch didn't apply cleanly against my source (which had RSDid == > 1.24.2.9). So I did the patch by hand. From what I can tell, the patch > merely removes the "case 'c':" option from the switch found at about > line 78. If so, I've patched my systems and everything seems well here.
Not quite. What the patch does is disable the -c option when the REQUEST_METHOD environment variable is set, i.e. when htsearch is called as a CGI, rather than from the command line. -- Gilles R. Detillieux E-mail: <[EMAIL PROTECTED]> Spinal Cord Research Centre WWW: http://www.scrc.umanitoba.ca/~grdetil Dept. Physiology, U. of Manitoba Phone: (204)789-3766 Winnipeg, MB R3E 3J7 (Canada) Fax: (204)789-3930 _______________________________________________ htdig-dev mailing list [EMAIL PROTECTED] https://lists.sourceforge.net/lists/listinfo/htdig-dev
