[ubuntu/focal-security] lxml 4.5.0-1ubuntu0.5 (Accepted)

Leonidas S. Barbosa leo.barbosa at canonical.com
Wed Jan 12 12:55:26 UTC 2022


lxml (4.5.0-1ubuntu0.5) focal-security; urgency=medium

  * SECURITY UPDATE: XSS vulnerability
    - debian/patches/CVE-2021-43818-*.patch: prevent "@import"
      from re-occurring in the CSS after replacements and remove
      SVG image data URLs since they can embed script content in
      src/lxml/html/clean.py, src/html/tests/test_clean.py.
    - CVE-2021-43818

Date: 2022-01-11 19:30:15.435228+00:00
Changed-By: leo.barbosa at canonical.com (Leonidas S. Barbosa)
https://launchpad.net/ubuntu/+source/lxml/4.5.0-1ubuntu0.5
-------------- next part --------------
Sorry, changesfile not available.


More information about the Focal-changes mailing list