Debian Security Advisory
DSA-3168-1 ruby-redcloth -- security update
- Date Reported:
- 22 Feb 2015
- Affected Packages:
- ruby-redcloth
- Vulnerable:
- Yes
- Security database references:
- In the Debian bugtracking system: Bug 774748.
In Mitre's CVE dictionary: CVE-2012-6684. - More information:
-
Kousuke Ebihara discovered that redcloth, a Ruby module used to convert Textile markup to HTML, did not properly sanitize its input. This allowed a remote attacker to perform a cross-site scripting attack by injecting arbitrary JavaScript code into the generated HTML.
For the stable distribution (wheezy), this problem has been fixed in version 4.2.9-2+deb7u2.
For the unstable distribution (sid), this problem has been fixed in version 4.2.9-4.
We recommend that you upgrade your ruby-redcloth packages.