Debian Security Advisory
DLA-167-1 redcloth -- LTS security update
- Date Reported:
- 07 Mar 2015
- Affected Packages:
- redcloth
- Vulnerable:
- Yes
- Security database references:
- In the Debian bugtracking system: Bug 774748.
In Mitre's CVE dictionary: CVE-2012-6684. - More information:
-
Kousuke Ebihara discovered that redcloth, a Ruby module used to convert Textile markup to HTML, did not properly sanitize its input. This allowed a remote attacker to perform a cross-site scripting attack by injecting arbitrary JavaScript code into the generated HTML.
For Debian 6
Squeeze
, these issues have been fixed in redcloth version 4.2.2-1.1+deb6u1