Login
Newsletter
Werbung

Sicherheit: Cross-Site Scripting in lxml (Aktualisierung)
Aktuelle Meldungen Distributionen
Name: Cross-Site Scripting in lxml (Aktualisierung)
ID: USN-4896-2
Distribution: Ubuntu
Plattformen: Ubuntu 14.04 ESM
Datum: Do, 8. April 2021, 22:43
Referenzen: https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2021-28957
Applikationen: lxml
Update von: Cross-Site Scripting in lxml

Originalnachricht


--===============7979733201159231065==
Content-Type: multipart/signed; micalg=pgp-sha512;
protocol="application/pgp-signature";
boundary="1yeeQ81UyVL57Vl7"
Content-Disposition: inline


--1yeeQ81UyVL57Vl7
Content-Type: text/plain; charset=us-ascii
Content-Disposition: inline

==========================================================================
Ubuntu Security Notice USN-4896-2
April 08, 2021

lxml vulnerability
==========================================================================

A security issue affects these releases of Ubuntu and its derivatives:

- Ubuntu 14.04 ESM

Summary:

lxml could allow cross-site scripting (XSS) attacks.

Software Description:
- lxml: pythonic binding for the libxml2 and libxslt libraries

Details:

USN-4896-1 fixed a vulnerability in lxml. This update provides
the corresponding update for Ubuntu 14.04 ESM.

Original advisory details:

It was discovered that lxml incorrectly handled certain HTML attributes. A
remote attacker could possibly use this issue to perform cross-site
scripting (XSS) attacks.

Update instructions:

The problem can be corrected by updating your system to the following
package versions:

Ubuntu 14.04 ESM:
python-lxml 3.3.3-1ubuntu0.2+esm3
python3-lxml 3.3.3-1ubuntu0.2+esm3

In general, a standard system update will make all the necessary changes.

References:
https://ubuntu.com/security/notices/USN-4896-2
https://ubuntu.com/security/notices/USN-4896-1
CVE-2021-28957

--1yeeQ81UyVL57Vl7
Content-Type: application/pgp-signature; name="signature.asc"

-----BEGIN PGP SIGNATURE-----

iQIzBAABCgAdFiEEf+ebRFcoyOoAQoOeRbznW4QLH2kFAmBvCU8ACgkQRbznW4QL
H2mqeRAArjmC5E3YdA61QrxEL31g/Uymhet0H4QlDnLBN4OiKD4FQ7dBeLTjjQo1
+A28BKkKK53T82PrBfjFUWeDslFkCSsXW8p/5X5IrKeFkD2SoJgtyTLN2sVf52qX
HgMZOUhF8DHQvXxWOeLb2wRafYxeUj36kiUm1gsW7CKxhxSl9TmVBjizMVKcfsNc
OA28wR8xi0f8TxldNzEbMp+15lw47d1+h5/6CI2HvFrx5zUl9PIGG69LITI5aPVm
CWtqj+Am+pwY9ClhOKGMg8knFhqhxgEe1Y0TzyD70TyCaq2n2EICJ7x3tpE/UGPf
wQ7jPYAb2C0RizQtqaWv13M8aWPoYJfSGak1Khm77fTcRNsVDcgPCorgllGL4XfW
3S4JJBchX/IxW//GibsiaOjwio61VHiVayppzhHztWFflEqU3ChQYw0FU8liHFuJ
5gFi1FrM7Rn/DYUJwKsHenMZX7xqXN6nK5aoZ6ShSdQZ6VXfaWoSJ7QZbmw8v4W+
jMZy3DETgYl3Z7d7dQ+PGQwTX2CPu6csawt4JxOhoJQMBaqs9XZnVFNEwLMo1Y5A
0Mav/Itd/cZLd/rvJ6v2Do2814gqBIoO5wH9sQQ6FTF7xPIp6wM7HS4FK7iRoCuU
WPtoW32Px3M1RyI64KVOUdM7ec4NgMcUPsDC4/TiIylIjO6qO8c=
=T8na
-----END PGP SIGNATURE-----

--1yeeQ81UyVL57Vl7--


--===============7979733201159231065==
Content-Type: text/plain; charset="utf-8"
MIME-Version: 1.0
Content-Transfer-Encoding: base64
Content-Disposition: inline

--
ubuntu-security-announce mailing list
ubuntu-security-announce@lists.ubuntu.com
Modify settings or unsubscribe at: https://lists.ubuntu.com/mailman/listinfo/ubuntu-security-announce
Pro-Linux
Pro-Linux @Facebook
Neue Nachrichten
Werbung