ELA-332-1 lxml security update

cross-site scripting

2020-12-15
Packagelxml
Version3.4.0-1+deb8u3


It was discovered that the clean_html() function of lxml, a Python library for HTML and XML processing, performed insufficient sanitisation for embedded Javascript code. This could lead to cross-site scripting or possibly the execution of arbitrary code.



For Debian 8 jessie, these problems have been fixed in version 3.4.0-1+deb8u3.

We recommend that you upgrade your lxml packages.

Further information about Extended LTS security advisories can be found in the dedicated section of our website.