-$Id: CHANGES,v 1.11 1999/11/02 09:35:55 tiniou Exp $
+$Id: CHANGES,v 1.13 1999/11/05 22:02:11 tiniou Exp $
-Changes between versions 0.4b7 and 0.4b8 (released ???????????????)
-===================================================================
+Changes between versions 0.4b8 and 0.4b9 (released November 5, 1999)
+====================================================================
+
+1. Use lchown instead of chown, fixing a possible security problem
+ when restoring symlinks (a malicious user could use this
+ to deliberately corrupt the ownership of important system files).
+ Thanks to Chris Siebenmann <cks@utcc.utoronto.ca> for detecting
+ this and providing the patch.
+
+Changes between versions 0.4b7 and 0.4b8 (released November 3, 1999)
+====================================================================
1. Put dump sources under CVS, added Id tags in all files so
one can use 'ident' on binary files.