[ubuntu/bionic-updates] lxml 4.2.1-1ubuntu0.6 (Accepted)
Ubuntu Archive Robot
ubuntu-archive-robot at lists.canonical.com
Wed Jan 12 13:58:43 UTC 2022
lxml (4.2.1-1ubuntu0.6) bionic-security; urgency=medium
* SECURITY UPDATE: XSS vulnerability
- debian/patches/CVE-2021-43818-*.patch: prevent "@import"
from re-occurring in the CSS after replacements and remove
SVG image data URLs since they can embed script content in
src/lxml/html/clean.py, src/html/tests/test_clean.py.
- CVE-2021-43818
Date: 2022-01-11 17:09:09.650092+00:00
Changed-By: leo.barbosa at canonical.com (Leonidas S. Barbosa)
Signed-By: Ubuntu Archive Robot <ubuntu-archive-robot at lists.canonical.com>
https://launchpad.net/ubuntu/+source/lxml/4.2.1-1ubuntu0.6
-------------- next part --------------
Sorry, changesfile not available.
More information about the Bionic-changes
mailing list