Mageia alert MGASA-2015-0206 (ruby-redcarpet)
From: | Mageia Updates <buildsystem-daemon@mageia.org> | |
To: | updates-announce@ml.mageia.org | |
Subject: | [updates-announce] MGASA-2015-0206: Updated ruby-redcarpet packages fix a security vulnerability | |
Date: | Mon, 11 May 2015 22:11:07 +0200 | |
Message-ID: | <20150511201107.B869743AA1@valstar.mageia.org> |
MGASA-2015-0206 - Updated ruby-redcarpet packages fix a security vulnerability Publication date: 11 May 2015 URL: http://advisories.mageia.org/MGASA-2015-0206.html Type: security Affected Mageia releases: 4 Description: Updated ruby-redcarpet packages fix security vulnerability: Redcarpet allows for possible XSS of untrusted markdown if the autolink extension is enabled. References: - https://bugs.mageia.org/show_bug.cgi?id=15652 - http://openwall.com/lists/oss-security/2015/04/07/11 SRPMS: - 4/core/ruby-redcarpet-3.0.0-1.1.mga4