Debian Security Advisory

DSA-3168-1 ruby-redcloth -- security update

Date Reported:
22 Feb 2015
Affected Packages:
ruby-redcloth
Vulnerable:
Yes
Security database references:
In the Debian bugtracking system: Bug 774748.
In Mitre's CVE dictionary: CVE-2012-6684.
More information:

Kousuke Ebihara discovered that redcloth, a Ruby module used to convert Textile markup to HTML, did not properly sanitize its input. This allowed a remote attacker to perform a cross-site scripting attack by injecting arbitrary JavaScript code into the generated HTML.

For the stable distribution (wheezy), this problem has been fixed in version 4.2.9-2+deb7u2.

For the unstable distribution (sid), this problem has been fixed in version 4.2.9-4.

We recommend that you upgrade your ruby-redcloth packages.