Debian Security Advisory

DLA-339-1 libhtml-scrubber-perl -- LTS security update

Date Reported:
03 Nov 2015
Affected Packages:
libhtml-scrubber-perl
Vulnerable:
Yes
Security database references:
In the Debian bugtracking system: Bug 803943.
In Mitre's CVE dictionary: CVE-2015-5667.
More information:

HTML::Scrubber is vulnerable to a cross-site scripting (XSS) vulnerability when the comment feature is enabled. It allows remote attackers to inject arbitrary web script or HTML via a crafted comment.

For Debian 6 squeeze, this has been fixed in libhtml-scrubber-perl version 0.08-4+deb6u1.