[DOMPurify Security] New Release Version 0.8.1 (Security Issue)

Security Announcements for DOMPurify and related tools dompurify-security at lists.ruhr-uni-bochum.de
Mon Jun 6 13:41:20 CEST 2016


*Intro*

A new version of DOMPurify was released today: DOMPurify 0.8.1

*Background*

A security issue was spotted by @neilj, exclusively affecting the
(default-off) ALLOW_UNKNOWN_PROTOCOLS mode, where malformed HTML could
cause XSS.

The problem was caused by a logical bug and has been reported and fixed
by @neilj.

*Example*

Details about the problem can be found here:
https://github.com/cure53/DOMPurify/blob/master/test/test-suite.js#L277

*Fix*

The fix commit is available here:
https://github.com/cure53/DOMPurify/pull/166/commits/feed055e967eff0553879ed2c1e1b71bee3bd46d

*Packages*

Updated packages are available here:
https://github.com/cure53/DOMPurify/releases/tag/0.8.1

EOF

-- 
Fon    +49 1520 8675782
PGP    0xD33441A8
S/MIME kuix.de/smime-keyserver/

cure53.de || mario.heideri.ch || 0x6D6172696F

-------------- next part --------------
A non-text attachment was scrubbed...
Name: signature.asc
Type: application/pgp-signature
Size: 490 bytes
Desc: OpenPGP digital signature
URL: <http://lists.ruhr-uni-bochum.de/pipermail/dompurify-security/attachments/20160606/e4e8292f/attachment.sig>


More information about the DOMPurify-Security mailing list