Vulnerability Bulletins

DSA-3168 ruby-redcloth - security update

   
Affected software Debian
 
Kousuke Ebihara discovered that redcloth, a Ruby module used toconvert Textile markup to HTML, did not properly sanitize itsinput. This allowed a remote attacker to perform a cross-sitescripting attack by injecting arbitrary JavaScript code into thegenerated HTML.

More info:

https://www.debian.org/security/2015/dsa-3168