Debian: Security Advisory for lxml (DSA-5043-1)

Information

Severity

Severity

Medium

Family

Family

Debian Local Security Checks

CVSSv2 Base

CVSSv2 Base

6.8

CVSSv2 Vector

CVSSv2 Vector

AV:N/AC:M/Au:N/C:P/I:P/A:P

Solution Type

Solution Type

Vendor Patch

Created

Created

4 months ago

Modified

Modified

4 months ago

Summary

The remote host is missing an update for the 'lxml' package(s) announced via the DSA-5043-1 advisory.

Insight

Insight

It was discovered that lxml, a Python binding for the libxml2 and libxslt libraries, does not properly sanitize its input, which could lead to cross-site scripting.

Affected Software

Affected Software

'lxml' package(s) on Debian Linux.

Detection Method

Detection Method

Checks if a vulnerable package version is present on the target host.

Solution

Solution

For the oldstable distribution (buster), this problem has been fixed in version 4.3.2-1+deb10u4. For the stable distribution (bullseye), this problem has been fixed in version 4.6.3+dfsg-0.1+deb11u1. We recommend that you upgrade your lxml packages.

Common Vulnerabilities and Exposures (CVE)

Want the latest vulnerabilities news?

Sign up to stay up to date. It is free and always will be.

Processing. Please wait...

We care about the protection of your data. Read our Privacy Policy.