-The 2.16.1 release fixes various bugs found in the 2.16
-release, including some security issues.
+The 2.16.2 release fixes some minor security issues in 2.16.1.
**************************
*** ABOUT THIS VERSION ***
*** Recommended Practice For The Upgrade ***
-As always, please ensure you have ran checksetup.pl after
+As always, please ensure you have run checksetup.pl after
replacing the files in your installation.
It is recommended that you view the sanity check page
option "The bug is resolved or verified" to achieve part of this.
(bug 130821)
-*********************************************
-*** USERS UPGRADING FROM 2.16 OR EARLIER ***
-*********************************************
+*****************************************************************
+*** USERS UPGRADING FROM 2.16.1 OR EARLIER, 2.14.4 OR EARLIER ***
+*****************************************************************
+
+*** SECURITY ISSUES RESOLVED ***
+
+- Fixed a cross site scriptability issue in quips. This is only a problem
+ if quips with HTML could have been inserted into your quips files. Bugzilla
+ has not allowed this since 2.12.
+ (bug 179329)
+- checksetup.pl will now attempt to prevent access to "editor backups" of
+ localconfig.
+ (bug 186383)
+- collectstats.pl no longer makes data/mining (which contains graphing
+ information) world writeable.
+ (bug 183188)
+
+***********************************************
+*** USERS UPGRADING FROM 2.16.0 OR EARLIER ***
+***********************************************
*** SECURITY ISSUES RESOLVED ***
See also next section.
******************************************************
-*** USERS UPGRADING FROM 2.14.3 OR EARLIER, 2.16.0 ***
+*** USERS UPGRADING FROM 2.16.0, 2.14.3 OR EARLIER ***
******************************************************
*** SECURITY ISSUES RESOLVED ***
(bug 160631)
***********************************************
-*** USERS UPGRADING FROM 2.14.4 OR EARLIER ***
+*** USERS UPGRADING FROM 2.14.5 OR EARLIER ***
***********************************************
*** SECURITY ISSUES RESOLVED ***
their only email preference was being added or removed from QA.
(bug 143091)
+***********************************************
+*** USERS UPGRADING FROM 2.14.4 OR EARLIER ***
+***********************************************
+
+See section above about users upgrading from 2.16.1 or earlier,
+2.14.4 or earlier.
+
***********************************************
*** USERS UPGRADING FROM 2.14.3 OR EARLIER ***
***********************************************