Bug#764885: Security flaws in the current Debian version

2014-10-16 Thread David Prévot
Hi, On Sat, Oct 11, 2014 at 04:57:25PM -0400, David Prévot wrote: > Package: php-htmlpurifier > Version: 4.4.0+dfsg1-1 > You may wish to maintain this package inside the PHP PEAR Maintainers > team and take advantage of the pkg-php-tools helper. As agreed with Roland, I’m taking the lead on this

Bug#764885: Security flaws in the current Debian version

2014-10-11 Thread David Prévot
Package: php-htmlpurifier Version: 4.4.0+dfsg1-1 Severity: serious Tags: security Hi, HTMLPurifier 4.6.0, published almost a year ago, “is a major security release, fixing numerous bad quadratic asymptotics in HTML Purifier's core algorithms.” according to upstream changelog. “Additionally, the s