On Wed, Jul 21, 2010 at 4:20 AM, Andrew White <andywhite at gmail dot com> wrote:
> was this introduced post 1.2.3-RC3 , which is listed as the version effected
Yep, we just committed our changes to 1.2.3 this week. 2.0 has had
commits off and on for a couple weeks now.
We do a lot more checking in 2.0 than we do in 1.2.3. On some things
we warn the user that it might be a dns rebind and on the other checks
we downright prevent the page from rendering with an error.