[DOMPurify Security] New Release Version 0.8.1 (Security Issue)
Security Announcements for DOMPurify and related tools
dompurify-security at lists.ruhr-uni-bochum.de
Mon Jun 6 13:41:20 CEST 2016
*Intro*
A new version of DOMPurify was released today: DOMPurify 0.8.1
*Background*
A security issue was spotted by @neilj, exclusively affecting the
(default-off) ALLOW_UNKNOWN_PROTOCOLS mode, where malformed HTML could
cause XSS.
The problem was caused by a logical bug and has been reported and fixed
by @neilj.
*Example*
Details about the problem can be found here:
https://github.com/cure53/DOMPurify/blob/master/test/test-suite.js#L277
*Fix*
The fix commit is available here:
https://github.com/cure53/DOMPurify/pull/166/commits/feed055e967eff0553879ed2c1e1b71bee3bd46d
*Packages*
Updated packages are available here:
https://github.com/cure53/DOMPurify/releases/tag/0.8.1
EOF
--
Fon +49 1520 8675782
PGP 0xD33441A8
S/MIME kuix.de/smime-keyserver/
cure53.de || mario.heideri.ch || 0x6D6172696F
-------------- next part --------------
A non-text attachment was scrubbed...
Name: signature.asc
Type: application/pgp-signature
Size: 490 bytes
Desc: OpenPGP digital signature
URL: <http://lists.ruhr-uni-bochum.de/pipermail/dompurify-security/attachments/20160606/e4e8292f/attachment.sig>
More information about the DOMPurify-Security
mailing list