Fedora alert FEDORA-2016-59ce8b61dd (rubygem-rails-html-sanitizer)
From: | updates@fedoraproject.org | |
To: | package-announce@lists.fedoraproject.org | |
Subject: | [SECURITY] Fedora 23 Update: rubygem-rails-html-sanitizer-1.0.3-1.fc23 | |
Date: | Sun, 28 Feb 2016 12:28:41 +0000 (UTC) | |
Message-ID: | <20160228122841.1D9AE60879F9@bastion01.phx2.fedoraproject.org> |
-------------------------------------------------------------------------------- Fedora Update Notification FEDORA-2016-59ce8b61dd 2016-02-28 08:31:31.054519 -------------------------------------------------------------------------------- Name : rubygem-rails-html-sanitizer Product : Fedora 23 Version : 1.0.3 Release : 1.fc23 URL : https://github.com/rails/rails-html-sanitizer Summary : This gem is responsible to sanitize HTML fragments in Rails applications Description : HTML sanitization for Rails applications. -------------------------------------------------------------------------------- Update Information: Security fix for CVE-2015-7578 CVE-2015-7579 CVE-2015-7580 -------------------------------------------------------------------------------- References: [ 1 ] Bug #1302014 - CVE-2015-7579 rubygem-rails-html-sanitizer: XSS vulnerability in Action View's strip_tags function https://bugzilla.redhat.com/show_bug.cgi?id=1302014 [ 2 ] Bug #1301920 - CVE-2015-7578 rails-html-sanitizer: XSS vulnerability due to unremoved attributes from tags https://bugzilla.redhat.com/show_bug.cgi?id=1301920 -------------------------------------------------------------------------------- This update can be installed with the "yum" update program. Use su -c 'yum update rubygem-rails-html-sanitizer' at the command line. For more information, refer to "Managing Software with yum", available at https://docs.fedoraproject.org/yum/. All packages are signed with the Fedora Project GPG key. More details on the GPG keys used by the Fedora Project can be found at https://fedoraproject.org/keys -------------------------------------------------------------------------------- _______________________________________________ package-announce mailing list package-announce@lists.fedoraproject.org https://admin.fedoraproject.org/mailman/listinfo/package-...