Hello folks. If you're running a Scoop site it would be worth your while
to update from cvs, since we've just committed a patch to close a hole
that allowed users to edit or submit new stories that appear to be
written by any arbitrary other user. As far as I know, any site that
allows users to write or edit any kind of story is affected by this.

You can update from CVS following the usual directions, or, if that's
inconvenient, you can simply apply the patch attached to this email.
It's a pretty small fix, and won't monkey with anything else on the
site.

Just save the patch in your scoop root directory, and type:

$] patch -p0 < aidbug.patch

That should do it.


--R

(Here's hoping this list will allow me to send an attachment...)
-------------- next part --------------
A non-text attachment was scrubbed...
Name: aidbug.patch
Type: text/x-patch
Size: 1553 bytes
Desc: not available
Url : http://lists.kuro5hin.org/pipermail/scoop-help/attachments/20060726/913cdbee/aidbug.bin