MGASA-2014-0218

Source
https://advisories.mageia.org/MGASA-2014-0218.html
Import Source
https://advisories.mageia.org/MGASA-2014-0218.json
JSON Data
https://api.osv.dev/v1/vulns/MGASA-2014-0218
Related
Published
2014-05-14T22:10:47Z
Modified
2014-05-14T22:10:36Z
Summary
Updated python-lxml package fix CVE-2014-3146
Details

Updated python-lxml packages fix security vulnerability:

The cleanhtml() function, provided by the lxml.html.clean module, did not properly clean HTML input if it included non-printed characters (\x01-\x08). A remote attacker could use this flaw to serve malicious content to an application using the cleanhtml() function to process HTML, possibly allowing the attacker to inject malicious code into a website generated by this application (CVE-2014-3146).

References
Credits

Affected packages

Mageia:3 / python-lxml

Package

Name
python-lxml
Purl
pkg:rpm/mageia/python-lxml?distro=mageia-3

Affected ranges

Type
ECOSYSTEM
Events
Introduced
0Unknown introduced version / All previous versions are affected
Fixed
3.0.1-2.1.mga3

Ecosystem specific

{
    "section": "core"
}

Mageia:4 / python-lxml

Package

Name
python-lxml
Purl
pkg:rpm/mageia/python-lxml?distro=mageia-4

Affected ranges

Type
ECOSYSTEM
Events
Introduced
0Unknown introduced version / All previous versions are affected
Fixed
3.2.4-1.1.mga4

Ecosystem specific

{
    "section": "core"
}