Bug#837148: Bug#837150: Fix XSS with data:html links and form actions

2017-03-09 Thread Mathieu Parent
2017-03-09 15:29 GMT+01:00 Salvatore Bonaccorso : > Hello! Hello Salvatore, > On Fri, Sep 09, 2016 at 11:08:55AM +0200, Mathieu Parent wrote: >> Will upload lastest version to sid shortly, and I plan to fix this in >> jessie too. > > Do you still plan to work on the jessie

Bug#837150: Fix XSS with data:html links and form actions

2017-03-09 Thread Salvatore Bonaccorso
Hello! On Fri, Sep 09, 2016 at 11:08:55AM +0200, Mathieu Parent wrote: > Will upload lastest version to sid shortly, and I plan to fix this in > jessie too. Do you still plan to work on the jessie update as well? I would tend to mark this (CVE-2016-5303, #837150) as no-dsa and propose to fix it

Bug#837150: Fix XSS with data:html links and form actions

2016-09-09 Thread Mathieu Parent
Package: php-horde-text-filter Version: 2.3.4-2 Severity: important Tags: security sid jessie Control: found -1 2.2.1-5 Hello, In the recent bunch of updates to Horde, I found this: https://github.com/horde/horde/commit/30d5506c20d26efbb9942fbdc6f981a0bd333b97 Will upload lastest version to