Lucene search

K
amazonAmazonALAS-2015-629
HistoryDec 14, 2015 - 10:00 a.m.

Medium: perl-HTML-Scrubber

2015-12-1410:00:00
alas.aws.amazon.com
8

2.6 Low

CVSS2

Attack Vector

NETWORK

Attack Complexity

HIGH

Authentication

NONE

Confidentiality Impact

NONE

Integrity Impact

PARTIAL

Availability Impact

NONE

AV:N/AC:H/Au:N/C:N/I:P/A:N

0.004 Low

EPSS

Percentile

72.9%

Issue Overview:

Cross-site scripting (XSS) vulnerability in the HTML-Scrubber module before 0.15 for Perl, when the comment feature is enabled, allows remote attackers to inject arbitrary web script or HTML via a crafted comment.

Affected Packages:

perl-HTML-Scrubber

Issue Correction:
Run yum update perl-HTML-Scrubber to update your system.

New Packages:

noarch:  
    perl-HTML-Scrubber-0.15-1.5.amzn1.noarch  
  
src:  
    perl-HTML-Scrubber-0.15-1.5.amzn1.src  

Additional References

Red Hat: CVE-2015-5667

Mitre: CVE-2015-5667

OSVersionArchitecturePackageVersionFilename
Amazon Linux1noarchperl-html-scrubber< 0.15-1.5.amzn1perl-HTML-Scrubber-0.15-1.5.amzn1.noarch.rpm

2.6 Low

CVSS2

Attack Vector

NETWORK

Attack Complexity

HIGH

Authentication

NONE

Confidentiality Impact

NONE

Integrity Impact

PARTIAL

Availability Impact

NONE

AV:N/AC:H/Au:N/C:N/I:P/A:N

0.004 Low

EPSS

Percentile

72.9%