Upstream information
Description
Cross-site scripting (XSS) vulnerability in actionpack/lib/action_view/helpers/sanitize_helper.rb in the strip_tags helper in Ruby on Rails before 3.0.17, 3.1.x before 3.1.8, and 3.2.x before 3.2.8 allows remote attackers to inject arbitrary web script or HTML via malformed HTML markup.NVD CVSS v2 Base Score: 4.3 (AV:N/AC:M/Au:N/C:N/I:P/A:N)
Novell/SUSE information
Novell Bugzilla entry: 775649 SUSE Security Advisories:- openSUSE-SU-2012:1218-1, published Wed, 19 Sep 2012 17:08:35 +0200 (CEST)
List of released packages
| Product(s) | Fixed package version(s) | References |
|---|---|---|
| SUSE Studio Extension for System z 1.2 SUSE Studio Onsite 1.2 [Appliance - Studio] SUSE Studio Standard Edition 1.2 WebYaST 1.2 |
| Builds SAT Patch Nr: 7027 |
| SUSE Cloud 1.0 SUSE Linux Enterprise Software Development Kit 11 SP2 |
| sle11-sp2-sdk.ppc sle11-sp2-sdk.x86 sle11-sp2-sdk.ia64 sle11-sp2-sdk.s390x sle11-sp2-sdk.x86-64 SAT Patch Nr: 6801 |
| SUSE Studio Extension for System z 1.2 SUSE Studio Onsite 1.2 [Appliance - Studio] SUSE Studio Standard Edition 1.2 WebYaST 1.2 |
| Builds SAT Patch Nr: 7031 |
| SUSE Studio Extension for System z 1.2 SUSE Studio Onsite 1.2 [Appliance - Studio] SUSE Studio Standard Edition 1.2 WebYaST 1.2 |
| webyast12.x86-64 webyast12.s390x slms1.2.x86-64 webyast12.ia64 webyast12.x86 webyast12.ppc studioonsite1.2.x86-64 studioonsite1.2.s390x SAT Patch Nr: 6802 |
| SUSE Linux Enterprise High Availability Extension 11 SP2 |
| Builds SAT Patch Nr: 7078 |
| SUSE Cloud 1.0 SUSE Linux Enterprise Software Development Kit 11 SP2 |
| Builds SAT Patch Nr: 7030 |
| SUSE Cloud 1.0 SUSE Linux Enterprise Software Development Kit 11 SP2 |
| Builds SAT Patch Nr: 7026 |
