Bug#746812: python-lxml: clean_html input sanitization flaw

2014-05-09 Thread Salvatore Bonaccorso
Control: retitle -1 python-lxml: CVE-2014-3146: clean_html input sanitization flaw Hi CVE-2014-3146 was assigned for this issue[1]. [1] http://www.openwall.com/lists/oss-security/2014/05/09/7 Regards, Salvatore -- To UNSUBSCRIBE, email to debian-bugs-dist-requ...@lists.debian.org with a su

Bug#746812: python-lxml: clean_html input sanitization flaw

2014-05-03 Thread Salvatore Bonaccorso
Source: lxml Severity: important Tags: security upstream fixed-upstream Hi It was found that the clean_html() function does not properly clean HTML input if it includes non-printed characters (\x01-\x08). For detail see [1], [2] and [3]. [1] http://seclists.org/fulldisclosure/2014/Apr/210 [2]