-----BEGIN PGP SIGNED MESSAGE----- Hash: SHA512 Format: 1.8 Date: Sat, 28 Sep 2024 18:38:59 +0300 Source: ruby-rails-html-sanitizer Architecture: source Version: 1.3.0-1+deb11u1 Distribution: bullseye-security Urgency: medium Maintainer: Debian Ruby Extras Maintainers <pkg-ruby-extras-maintainers@lists.alioth.debian.org> Changed-By: Adrian Bunk <bunk@debian.org> Changes: ruby-rails-html-sanitizer (1.3.0-1+deb11u1) bullseye-security; urgency=medium . * Non-maintainer upload by the LTS Team. * CVE-2022-23517: Inefficient Regular Expression Complexity * CVE-2022-23518: XSS in data URIs * CVE-2022-23519: XSS vulnerability * CVE-2022-23520: XSS vulnerability * CVE-2022-32209: XSS vulnerability * Bump dependency on ruby-loofah due to new functionality used by the above fixes. Checksums-Sha1: d203ed00a492ffc04fc1e434c47978b53d67842a 2325 ruby-rails-html-sanitizer_1.3.0-1+deb11u1.dsc 0299be532576c062138bd0773e1ecf345411f163 12936 ruby-rails-html-sanitizer_1.3.0.orig.tar.gz 46c6284d703799ad59446cde45cccc760e834713 5980 ruby-rails-html-sanitizer_1.3.0-1+deb11u1.debian.tar.xz Checksums-Sha256: 7becdc44db6fc5a8ded0e5ba1b1d17f7e17e0610d412150b327af18cf85c25f6 2325 ruby-rails-html-sanitizer_1.3.0-1+deb11u1.dsc 5db2676eec0b14c3d405c516b5867852264f90f196d9a9fd262111dcd9666eb8 12936 ruby-rails-html-sanitizer_1.3.0.orig.tar.gz ca5e96adf50f59c8407010404bc618c09ecb38d636bd7def23ae77536d045328 5980 ruby-rails-html-sanitizer_1.3.0-1+deb11u1.debian.tar.xz Files: 862351934c55905767cdb6793c53f954 2325 ruby optional ruby-rails-html-sanitizer_1.3.0-1+deb11u1.dsc 435817b1d754880299fb0a044f17a050 12936 ruby optional ruby-rails-html-sanitizer_1.3.0.orig.tar.gz 7ecd86ae17ab3a92eac54fe87f5e4e5b 5980 ruby optional ruby-rails-html-sanitizer_1.3.0-1+deb11u1.debian.tar.xz -----BEGIN PGP SIGNATURE----- iQIyBAEBCgAdFiEEOvp1f6xuoR0v9F3wiNJCh6LYmLEFAmb4RTUACgkQiNJCh6LY mLEpyA/45vGs/lvcvCC8O/kvtpu8YHXnEFd5Gb+2CIOnmO4z0Qnl6MLbpaHxN1Bn Hw9Jnz+8YW2toDMvTT3x0KGKmWjqa13diJ6BgR1+jxKKdkUHK4U5tsS/0wehTytS Crw/egDZzXLgP5ZlM1yDDoPMWAIYoSOv2vREL1rNxjmwb44d7OjhMWJlyBmuzt+b f3PNuIp+pjt/iIGFcJYjlprR839Cgu7FtRKhZJvItFudjNv9HKJsOIxryNK5Z6s9 jMJPhlQGVuIgyUw1WopEAzyyWxy+L/KI5MsOILtUDnOEWVQSZwFV7IIRV8IOQUIK a/+FWZEatkfgCx42sLsrRsBfdAOWYGmeXpIp6bayLcv1zOxIzjN/AetKk7uypknm /eK6f/7Q6GAYSuxrTnimpDtzofAX1/e20cv19tVEHju+g4rhpDb5mSmGjI3IXnxv o8EWM1Xj1t4MQOTdXX/yHC+dU8Q4yc4shwaViuFVpSCdbNLVkIl3wku4ep3NPFz0 E7BD335nvICwvxqa44BA/B8Ob6NdmkQJnHOWOqnE7eQufRCYi/VpM6KbBQZLyy0Z nZnLS1gnCfozdtWjO844w/igAN5mMtarkaAoi2RDM6LVCPmY9zIcALm3zLyRGKSB /HN7R9lydj6sEF/iRzr7KHzm8Dpms7pAUHF5RwrYKvNvJvhK9A== =Btky -----END PGP SIGNATURE-----