MGASA-2018-0066

Source
https://advisories.mageia.org/MGASA-2018-0066.html
Import Source
https://advisories.mageia.org/MGASA-2018-0066.json
JSON Data
https://api.osv.dev/v1/vulns/MGASA-2018-0066
Related
Published
2018-01-07T16:06:39Z
Modified
2018-01-07T15:57:45Z
Summary
Updated python-mistune packages fix security vulnerabilities
Details

mistune.py in Mistune 0.7.4 allows XSS via an unexpected newline (such as in java\nscript:) or a crafted email address, related to the escape and autolink functions (CVE-2017-15612).

A cross-site-scripting vulnerability was found in python-mistune (CVE-2017-16876).

References
Credits

Affected packages

Mageia:6 / python-mistune

Package

Name
python-mistune
Purl
pkg:rpm/mageia/python-mistune?arch=source&distro=mageia-6

Affected ranges

Type
ECOSYSTEM
Events
Introduced
0Unknown introduced version / All previous versions are affected
Fixed
0.7.2-1.1.mga6

Ecosystem specific

{
    "section": "core"
}