oss-sec mailing list archives

Re: CVE id request: mahara / HTML Purifier


From: Josh Bressers <bressers () redhat com>
Date: Mon, 18 Apr 2011 16:02:01 -0400 (EDT)

----- Original Message -----
Could we get CVE id(s) for these security problems discovered in
HTML Purifier (emedded in older versions of mahara as well).

Patches are attached.

They originate from HTML Purifier

http://htmlpurifier.org/news/2011/0327-4.3.0-released


I find their advisory confusing. Can you break out which changelog entries
the patches are for?

Thanks.

-- 
    JB


Current thread: