lxml 4.5.2-1ubuntu0.1 source package in Ubuntu

Changelog

lxml (4.5.2-1ubuntu0.1) groovy-security; urgency=medium

  * SECURITY UPDATE: XSS vulnerability
    - Prevent combinations of <noscript> and <style> to sneak
      JS through the HTML cleaner in src/lxml/html/clean.py,
      src/lxml/html/tests/test_clean.py.
    - CVE-2020-27783

 -- Leonidas Da Silva Barbosa <email address hidden>  Tue, 08 Dec 2020 13:56:06 -0300

Upload details

Uploaded by:
Leonidas S. Barbosa on 2020-12-08
Uploaded to:
Groovy
Original maintainer:
Ubuntu Developers
Architectures:
any all
Section:
python
Urgency:
Medium Urgency

See full publishing history Publishing

Series Pocket Published Component Section

Downloads

File Size SHA-256 Checksum
lxml_4.5.2.orig.tar.gz 4.3 MiB cdc13a1682b2a6241080745b1953719e7fe0850b40a5c71ca574f090a1391df6
lxml_4.5.2-1ubuntu0.1.debian.tar.xz 8.1 KiB 1005e031bf1a69dcd7805ba82d8b24aea6c0ecde76eeac800eef834c82f8fd48
lxml_4.5.2-1ubuntu0.1.dsc 2.0 KiB e1d03864d7424d1a91ce20c5e38c4168a787cb0650f85e2e0679229d13bcac78

View changes file

Binary packages built by this source

python-lxml-doc: pythonic binding for the libxml2 and libxslt libraries (documentation)

 lxml is a new Python binding for libxml2 and libxslt, completely
 independent from these existing Python bindings.
 .
 This package contains the html documentation.

python3-lxml: pythonic binding for the libxml2 and libxslt libraries

 lxml is a new Python binding for libxml2 and libxslt, completely
 independent from existing Python bindings. Its aim:
 .
   * Pythonic API.
   * Documented.
   * Use Python unicode strings in API.
   * Safe (no segfaults).
   * No manual memory management!
 .
 lxml aims to provide a Pythonic API by following as much as possible
 the ElementTree API, trying to avoid inventing too many new APIs,
 or the user's having to learn new things -- XML is complicated enough.

python3-lxml-dbg: pythonic binding for the libxml2 and libxslt libraries (debug extension)

 lxml is a new Python binding for libxml2 and libxslt, completely
 independent from existing Python bindings.
 .
 This package contains the extension built for the Python3 debug interpreter.