Overly broad permissions can turn one compromised account into a much larger security problem. Learn how to reduce unnecessary access, review privileges, and apply least privilege across modern Linux systems. Review Linux Privileges×

Alerts This Week
Warning Icon 1 523
Alerts This Week
Warning Icon 1 523

Fedora 23: perl-HTML-Scrubber Moderate Security Advisory for XSS

fedora
Calendar Grey November 30, 2015
Scroller Fedora
CentOS patches perl-HTML-Scrubber to address XSS vulnerability. Use dnf for improved HTML protection.
perl-HTML-Scrubber-0.15-1.fc21 - update to 0.15 perl-HTML- Scrubber-0.15-1.fc22 - update to 0.15 perl-HTML-Scrubber-0.15-1.fc23 - update to 0.15

Summary

If you wanna "scrub" or "sanitize" html input in a reliable an flexible

fashion, then this module is for you.

I wasn't satisfied with HTML::Sanitizer because it is based on

HTML::TreeBuilder, so I thought I'd write something similar that works

directly with HTML::Parser.

Update Information:

perl-HTML-Scrubber-0.15-1.fc21 - update to 0.15 perl-HTML- Scrubber-0.15-1.fc22 - update to 0.15 perl-HTML-Scrubber-0.15-1.fc23 - update to 0.15

Change Log

References


[ 1 ] Bug #1276647 - CVE-2015-5667 perl-HTML-Scrubber: XSS vulnerability when function "comment" is enabled [fedora-all] https://bugzilla.redhat.com/show_bug.cgi?id=1276647

Update Instructions

This update can be installed with the "yum" update program. Use su -c 'yum update perl-HTML-Scrubber' at the command line. For more information, refer to "Managing Software with yum", available at .

Name: perl-HTML-Scrubber
Product: Fedora 23
Version: 0.15
Release: 1.fc23
Summary: Library for scrubbing/sanitizing html

Get the latest News and Insights

Get the latest Linux and open source security news straight to your inbox.