Debian Security Advisory
DLA-339-1 libhtml-scrubber-perl -- LTS security update
- Date Reported:
- 03 Nov 2015
- Affected Packages:
- libhtml-scrubber-perl
- Vulnerable:
- Yes
- Security database references:
- In the Debian bugtracking system: Bug 803943.
In Mitre's CVE dictionary: CVE-2015-5667. - More information:
-
HTML::Scrubber is vulnerable to a cross-site scripting (XSS) vulnerability when the comment feature is enabled. It allows remote attackers to inject arbitrary web script or HTML via a crafted comment.
For Debian 6 squeeze, this has been fixed in libhtml-scrubber-perl version 0.08-4+deb6u1.