[SECURITY] Fedora 20 Update: php-htmlpurifier-htmlpurifier-4.6.0-1.fc20

updates at fedoraproject.org updates at fedoraproject.org
Sat Aug 23 01:56:29 UTC 2014


--------------------------------------------------------------------------------
Fedora Update Notification
FEDORA-2014-9361
2014-08-15 01:47:10
--------------------------------------------------------------------------------

Name        : php-htmlpurifier-htmlpurifier
Product     : Fedora 20
Version     : 4.6.0
Release     : 1.fc20
URL         : http://www.htmlpurifier.org
Summary     : Standards-compliant HTML filter library
Description :
Standards-compliant HTML filter library written in PHP. HTML Purifier
will not only remove all malicious code (better known as XSS) with a
thoroughly audited, secure yet permissive white list, it will also make
sure your documents are standards compliant, something only achievable
with a comprehensive knowledge of W3C's specifications.

--------------------------------------------------------------------------------
Update Information:

HTML Purifier 4.6.0 is a major security release, fixing numerous bad quadratic asymptotics in HTML Purifier's core algorithms.  Most users will see a decent speedup on large inputs, although small inputs may take longer.  Additionally, the secure URI munging algorithm has changed to do a proper HMAC.  There are some other miscellaneous bugfixes as well.
--------------------------------------------------------------------------------
ChangeLog:

* Sun Aug 10 2014 Robert Scheck <robert at fedoraproject.org> 4.6.0-1
- Upgrade to 4.6.0 (#1038530)
* Sat Jun  7 2014 Fedora Release Engineering <rel-eng at lists.fedoraproject.org> - 4.3.0-7
- Rebuilt for https://fedoraproject.org/wiki/Fedora_21_Mass_Rebuild
--------------------------------------------------------------------------------
References:

  [ 1 ] Bug #1038530 - php-htmlpurifier-htmlpurifier: hash length extension in HTMLPurifier
        https://bugzilla.redhat.com/show_bug.cgi?id=1038530
--------------------------------------------------------------------------------

This update can be installed with the "yum" update program.  Use
su -c 'yum update php-htmlpurifier-htmlpurifier' at the command line.
For more information, refer to "Managing Software with yum",
available at http://docs.fedoraproject.org/yum/.

All packages are signed with the Fedora Project GPG key.  More details on the
GPG keys used by the Fedora Project can be found at
https://fedoraproject.org/keys
--------------------------------------------------------------------------------


More information about the package-announce mailing list