Debian Security Advisory

DLA-167-1 redcloth -- LTS security update

Date Reported:
07 Mar 2015
Affected Packages:
redcloth
Vulnerable:
Yes
Security database references:
In the Debian bugtracking system: Bug 774748.
In Mitre's CVE dictionary: CVE-2012-6684.
More information:

Kousuke Ebihara discovered that redcloth, a Ruby module used to convert Textile markup to HTML, did not properly sanitize its input. This allowed a remote attacker to perform a cross-site scripting attack by injecting arbitrary JavaScript code into the generated HTML.

For Debian 6 Squeeze, these issues have been fixed in redcloth version 4.2.2-1.1+deb6u1