Debian Security Advisory
DLA-1604-1 lxml -- LTS security update
- Date Reported:
- 10 Dec 2018
- Affected Packages:
- Security database references:
- In Mitre's CVE dictionary: CVE-2018-19787.
- More information:
It was discovered that there was a XSS injection vulnerability in the LXML HTML/XSS manipulation library for Python.
j a v a s c r i p t. This is a similar issue to CVE-2014-3146.
For Debian 8
Jessie, this issue has been fixed in lxml version 3.4.0-1+deb8u1.
We recommend that you upgrade your lxml packages.