[Date Prev][Date Next] [Thread Prev][Thread Next] [Date Index] [Thread Index]

Bug#494204: marked as done (ITP: libhtml-stripscripts-perl -- Strip scripting constructs out of HTML)



Your message dated Sun, 10 Aug 2008 01:46:16 +0000
with message-id <E1KS00e-0007PH-G5@ries.debian.org>
and subject line Bug#494204: fixed in libhtml-stripscripts-perl 1.04-1
has caused the Debian Bug report #494204,
regarding ITP: libhtml-stripscripts-perl -- Strip scripting constructs out of HTML
to be marked as done.

This means that you claim that the problem has been dealt with.
If this is not the case it is now your responsibility to reopen the
Bug report if necessary, and/or fix the problem forthwith.

(NB: If you are a system administrator and have no idea what this
message is talking about, this may indicate a serious mail system
misconfiguration somewhere. Please contact owner@bugs.debian.org
immediately.)


-- 
494204: http://bugs.debian.org/cgi-bin/bugreport.cgi?bug=494204
Debian Bug Tracking System
Contact owner@bugs.debian.org with problems
--- Begin Message ---
Package: wnpp
Severity: wishlist
Owner: Tim Retout <tim@retout.co.uk>

* Package name    : libhtml-stripscripts-perl
  Version         : 1.04
  Upstream Author : Clinton Gormley <clint@traveljury.com>
* URL             : http://search.cpan.org/dist/HTML-StripScripts/
* License         : Artistic | GPL-1+
  Programming Lang: Perl
  Description     : Strip scripting constructs out of HTML

HTML::StripScripts strips scripting constructs out of HTML, leaving as
much non-scripting markup in place as possible.  This allows web
applications to display HTML originating from an untrusted source
without introducing XSS (cross site scripting) vulnerabilities.

You will probably use HTML::StripScripts::Parser rather than using
this module directly - see the libhtml-stripscripts-parser-perl
package.

The process is based on whitelists of tags, attributes and attribute
values.  This approach is the most secure against disguised scripting
constructs hidden in malicious HTML documents.

As well as removing scripting constructs, this module ensures that
there is a matching end for each start tag, and that the tags are
properly nested.



--- End Message ---
--- Begin Message ---
Source: libhtml-stripscripts-perl
Source-Version: 1.04-1

We believe that the bug you reported is fixed in the latest version of
libhtml-stripscripts-perl, which is due to be installed in the Debian FTP archive:

libhtml-stripscripts-perl_1.04-1.diff.gz
  to pool/main/libh/libhtml-stripscripts-perl/libhtml-stripscripts-perl_1.04-1.diff.gz
libhtml-stripscripts-perl_1.04-1.dsc
  to pool/main/libh/libhtml-stripscripts-perl/libhtml-stripscripts-perl_1.04-1.dsc
libhtml-stripscripts-perl_1.04-1_all.deb
  to pool/main/libh/libhtml-stripscripts-perl/libhtml-stripscripts-perl_1.04-1_all.deb
libhtml-stripscripts-perl_1.04.orig.tar.gz
  to pool/main/libh/libhtml-stripscripts-perl/libhtml-stripscripts-perl_1.04.orig.tar.gz



A summary of the changes between this version and the previous one is
attached.

Thank you for reporting the bug, which will now be closed.  If you
have further comments please address them to 494204@bugs.debian.org,
and the maintainer will reopen the bug report if appropriate.

Debian distribution maintenance software
pp.
Tim Retout <tim@retout.co.uk> (supplier of updated libhtml-stripscripts-perl package)

(This message was generated automatically at their request; if you
believe that there is a problem with it please contact the archive
administrators by mailing ftpmaster@debian.org)


-----BEGIN PGP SIGNED MESSAGE-----
Hash: SHA1

Format: 1.8
Date: Thu, 7 Aug 2008 17:21:30 -0300
Source: libhtml-stripscripts-perl
Binary: libhtml-stripscripts-perl
Architecture: source all
Version: 1.04-1
Distribution: unstable
Urgency: low
Maintainer: Debian Perl Group <pkg-perl-maintainers@lists.alioth.debian.org>
Changed-By: Tim Retout <tim@retout.co.uk>
Description: 
 libhtml-stripscripts-perl - Strip scripting constructs out of HTML
Closes: 494204
Changes: 
 libhtml-stripscripts-perl (1.04-1) unstable; urgency=low
 .
   * Initial Release. (Closes: #494204)
Checksums-Sha1: 
 d47745296ebeb6a36036184b30349f1fc7e387b7 1444 libhtml-stripscripts-perl_1.04-1.dsc
 2d12b84ad9c2eef25683082ee5ce95919e80652c 43708 libhtml-stripscripts-perl_1.04.orig.tar.gz
 876ca1f6e264e9859ea17750439ddcbebc4acf17 1622 libhtml-stripscripts-perl_1.04-1.diff.gz
 fe671f45c3d123d82f77be475461c9509b0f95db 34336 libhtml-stripscripts-perl_1.04-1_all.deb
Checksums-Sha256: 
 bc2d581937b637e380ea34abda8d2be5e09d9e288b4a08cf0a3e36a317f501c1 1444 libhtml-stripscripts-perl_1.04-1.dsc
 6d6cd9c2eaefb14ed80f5ef60a746979887783bed05ee92d3be9ec0a5cf8c33d 43708 libhtml-stripscripts-perl_1.04.orig.tar.gz
 155fc236207fab44bdef60bfca8c70d72edde2904bb87fcaca85ced46f590ee3 1622 libhtml-stripscripts-perl_1.04-1.diff.gz
 2600e8f72071f4b5df93c3a2723b7445c77081193175b12d6f0ab4e268bd95a3 34336 libhtml-stripscripts-perl_1.04-1_all.deb
Files: 
 43267fc69181c4cb98f8f2498f3c4151 1444 perl optional libhtml-stripscripts-perl_1.04-1.dsc
 aecd01e273bddbf60dca2a923163826d 43708 perl optional libhtml-stripscripts-perl_1.04.orig.tar.gz
 e12852391fa5a0409f7f75be4e24bcf7 1622 perl optional libhtml-stripscripts-perl_1.04-1.diff.gz
 041b6f76c6367558f84fb07f4a5a1dd5 34336 perl optional libhtml-stripscripts-perl_1.04-1_all.deb

-----BEGIN PGP SIGNATURE-----
Version: GnuPG v1.4.9 (GNU/Linux)

iEYEARECAAYFAkibhaoACgkQOzKYnQDzz+RGcgCfYxX1/ocuCAInIXxJXL6TXm3/
K50An0cj2dexv3KL5zl4vXwVtF3ePhZl
=TODU
-----END PGP SIGNATURE-----



--- End Message ---

Reply to: