On Mon, 10 Jul 2017 22:02:20 +0200 =?utf-8?q?Joonas_Kylm=C3=A4l=C3=A4?= wrote:
> Package: youtube-dl
> Version: 2017.05.18.1-1
> Severity: normal
>
> Dear Maintainer,
>
> Recently Trisquel GNU/Linux users discovered that youtube-dl might in
> some cases execute (as far as I understood) arbitary JavaScript served
> by the web server it connects to, and thus be harmful for the
> user. See
> . Can
> we somehow work around these JavaScript requirements? At least I think
> it would be a good thing to warning the user about arbitary JavaScript
> being run as I, for example, didn't expect that a cli application
> would run JavaScript.
>
> Joonas


There's a further discussion about this linked from that trisquel page, with further interesting details and logic:

https://lists.nongnu.org/archive/html/gnu-linux-libre/2017-07/msg00003.html

Reply via email to