-----BEGIN PGP SIGNED MESSAGE----- Hash: SHA512 Format: 1.8 Date: Wed, 29 Oct 2020 19:03:02 +0200 Source: dompurify.js Binary: libjs-dompurify node-dompurify Architecture: source all Version: 0.8.2~dfsg1-1+deb9u1 Distribution: stretch-security Urgency: medium Maintainer: Debian Javascript Maintainers <pkg-javascript-devel@lists.alioth.debian.org> Changed-By: Thorsten Alteholz <debian@alteholz.de> Description: libjs-dompurify - XSS sanitizer for HTML, MathML and SVG node-dompurify - XSS sanitizer for HTML, MathML and SVG - Node.js module Changes: dompurify.js (0.8.2~dfsg1-1+deb9u1) stretch-security; urgency=medium . * Non-maintainer upload by the LTS Team. * CVE-2020-26870 and CVE-2019-16728 Fix for two mXSS issues in SVG- or MATH-elements. Checksums-Sha1: 7938e7b48335dc10e32768d0a6d920096bfbb1bb 2281 dompurify.js_0.8.2~dfsg1-1+deb9u1.dsc 020c45d558c38b1c1000b905fe4e1e31ca7e97e1 81279 dompurify.js_0.8.2~dfsg1.orig.tar.gz 3a9e9d36300998e587969b1c1cd4146943b06508 7816 dompurify.js_0.8.2~dfsg1-1+deb9u1.debian.tar.xz f114c5e63a899e1b0a64650ae25d25cd8d1a10b3 8304 dompurify.js_0.8.2~dfsg1-1+deb9u1_amd64.buildinfo 005418cd5bafc3aa1da17b3ed10e22024af0d24a 19046 libjs-dompurify_0.8.2~dfsg1-1+deb9u1_all.deb d1c8864bc77be095602ef4f7fd572c1e17cbcbcc 16888 node-dompurify_0.8.2~dfsg1-1+deb9u1_all.deb Checksums-Sha256: 5a33fb0ddd4a41b7d45561b475db1ad8d9b9796ade3e16822cef7aaa872a1667 2281 dompurify.js_0.8.2~dfsg1-1+deb9u1.dsc 61524991c36905a1b9d7dcca1ea5ad5f2fe510cbe1dde5a20e2c2adeee9cddc9 81279 dompurify.js_0.8.2~dfsg1.orig.tar.gz 9667db90331af18f745fb960bbe085314a91e60c93dfab5f9ef96d9edae6685f 7816 dompurify.js_0.8.2~dfsg1-1+deb9u1.debian.tar.xz e75662949c30059798888959073c21565ed9cff461b952fec33066e3412f1886 8304 dompurify.js_0.8.2~dfsg1-1+deb9u1_amd64.buildinfo f427c5354c61cf6f05c5b4fd93689c0dbfac2973fbcb86e5e5be4e9e4e969a67 19046 libjs-dompurify_0.8.2~dfsg1-1+deb9u1_all.deb 025c8772f48faae97661897ac47915cffd8909f027629270449d39fcd9d7ee53 16888 node-dompurify_0.8.2~dfsg1-1+deb9u1_all.deb Files: ed362a6f9a4b7d15106f367f78354bb2 2281 web extra dompurify.js_0.8.2~dfsg1-1+deb9u1.dsc 467239bbc99f1c4c584c00c600e28d4b 81279 web extra dompurify.js_0.8.2~dfsg1.orig.tar.gz d018f41dcef7473acae83bb2cf5e5f50 7816 web extra dompurify.js_0.8.2~dfsg1-1+deb9u1.debian.tar.xz 4104bcbf6da3d15e7331b9c0dfa7321e 8304 web extra dompurify.js_0.8.2~dfsg1-1+deb9u1_amd64.buildinfo 7d9264701246bb919195701b964ef62d 19046 web extra libjs-dompurify_0.8.2~dfsg1-1+deb9u1_all.deb f6adf2e47b53124d825dfda2883af13c 16888 web extra node-dompurify_0.8.2~dfsg1-1+deb9u1_all.deb -----BEGIN PGP SIGNATURE----- iQKnBAEBCgCRFiEEYgH7/9u94Hgi6ruWlvysDTh7WEcFAl+a3mFfFIAAAAAALgAo aXNzdWVyLWZwckBub3RhdGlvbnMub3BlbnBncC5maWZ0aGhvcnNlbWFuLm5ldDYy MDFGQkZGREJCREUwNzgyMkVBQkI5Njk2RkNBQzBEMzg3QjU4NDcTHGRlYmlhbkBh bHRlaG9sei5kZQAKCRCW/KwNOHtYR08yD/0T2YSC3/xRzLrMTp9CR5KfckMuAX+C Bacm02SvdsMZXsblaxVS/PIvZycQccBOJq2TcVP0Q5pjcR0syXwe0troCJs6t+HO jWMUpyVka2CJtFZEQ+oiQdm4PiAkBlWOYoM0HHTEEsK6RuJ0hDqRLnw+A6NnlSYU kMof8/5kIS4VLTsbQm2h1Xbplj65fKwCn0cVl2CTpmT5+1duuoJnjSxBvlh/Mkuw rLTZXaytiwRFF+KZukNjHEsTD8b55rU7JISoTu28Tqd0sbNW2ZbJRhMnNsWK0XPe jCsxH9nfazAp/g1bdM311OehkaPvuoBeZKm7gw+NapakEu5cpZQxXRQmJu8tDsch UZmtSwpry2pKidrpHrpog/lv3If/cJvqBXhqUn4wWnbBy2VQL/9goBuOoqKLz8wH RthmpYc7LTr2ASfBeLs1piH/+Brz9vThEkTNGEftA5sICexmxcqWPAU2msEtewWt MHAJvfNybmoKRsKV+ROw+X1jN8ZqPGkTBjZC4GKyTUOrfKf8JW5SqdL5YM77mO2w SAwWMptrP1n878ctOEg0DB+aVOq9tkM7MBbofb6aOPv6rO2Ok+92za3058YnMSVv Psl+u33O98cwfP3FWrmkepOvpNaBT+sDn+bEoEVHRJK7ruhy1ewVZ/QZT6+LQUal dVqe3gxXMof8fg== =bp1h -----END PGP SIGNATURE-----