Bug#963808: ruby-sanitize: CVE-2020-4054: HTML sanitization bypass in Sanitize

2020-07-14 Thread Salvatore Bonaccorso
Hi Antonio, On Tue, Jul 14, 2020 at 09:41:21AM -0300, terce...@debian.org wrote: > On Mon, Jul 13, 2020 at 10:04:10PM +0200, Salvatore Bonaccorso wrote: > > Hi Antonio, > > > > On Mon, Jul 13, 2020 at 11:19:38AM -0300, terce...@debian.org wrote: > > > On Sun, Jul 12, 2020 at 03:11:30PM +0200, Sal

Bug#963808: ruby-sanitize: CVE-2020-4054: HTML sanitization bypass in Sanitize

2020-07-14 Thread terceiro
On Mon, Jul 13, 2020 at 10:04:10PM +0200, Salvatore Bonaccorso wrote: > Hi Antonio, > > On Mon, Jul 13, 2020 at 11:19:38AM -0300, terce...@debian.org wrote: > > On Sun, Jul 12, 2020 at 03:11:30PM +0200, Salvatore Bonaccorso wrote: > > > On Sat, Jun 27, 2020 at 09:10:01PM +0200, Salvatore Bonaccors

Bug#963808: ruby-sanitize: CVE-2020-4054: HTML sanitization bypass in Sanitize

2020-07-13 Thread Salvatore Bonaccorso
Hi Antonio, On Mon, Jul 13, 2020 at 11:19:38AM -0300, terce...@debian.org wrote: > On Sun, Jul 12, 2020 at 03:11:30PM +0200, Salvatore Bonaccorso wrote: > > On Sat, Jun 27, 2020 at 09:10:01PM +0200, Salvatore Bonaccorso wrote: > > > Source: ruby-sanitize > > > Version: 4.6.6-2 > > > Severity: grav

Bug#963808: ruby-sanitize: CVE-2020-4054: HTML sanitization bypass in Sanitize

2020-07-13 Thread terceiro
On Sun, Jul 12, 2020 at 03:11:30PM +0200, Salvatore Bonaccorso wrote: > On Sat, Jun 27, 2020 at 09:10:01PM +0200, Salvatore Bonaccorso wrote: > > Source: ruby-sanitize > > Version: 4.6.6-2 > > Severity: grave > > Tags: security upstream > > Justification: user security hole > > > > Hi, > > > > Th

Bug#963808: ruby-sanitize: CVE-2020-4054: HTML sanitization bypass in Sanitize

2020-07-12 Thread Salvatore Bonaccorso
On Sat, Jun 27, 2020 at 09:10:01PM +0200, Salvatore Bonaccorso wrote: > Source: ruby-sanitize > Version: 4.6.6-2 > Severity: grave > Tags: security upstream > Justification: user security hole > > Hi, > > The following vulnerability was published for ruby-sanitize. > > CVE-2020-4054[0]: > | In S

Bug#963808: ruby-sanitize: CVE-2020-4054: HTML sanitization bypass in Sanitize

2020-06-27 Thread Salvatore Bonaccorso
Source: ruby-sanitize Version: 4.6.6-2 Severity: grave Tags: security upstream Justification: user security hole Hi, The following vulnerability was published for ruby-sanitize. CVE-2020-4054[0]: | In Sanitize (RubyGem sanitize) greater than or equal to 3.0.0 and less | than 5.2.1, there is a cr