Overly broad permissions can turn one compromised account into a much larger security problem. Learn how to reduce unnecessary access, review privileges, and apply least privilege across modern Linux systems. Review Linux Privileges×

Alerts This Week
Warning Icon 1 465
Alerts This Week
Warning Icon 1 465

Ubuntu: 2217-1 Moderate Advisory on lxml XSS Security Threat

ubuntu
Calendar Grey May 21, 2014
Scroller Ubuntu
=========================================================================Ubuntu Security Notice USN-
lxml could allow cross-site scripting (XSS) attacks.

Summary

lxml could allow cross-site scripting (XSS) attacks.

Software Description:

- lxml: pythonic binding for the libxml2 and libxslt libraries

Details:

It was discovered that the lxml.html.clean module incorrectly stripped

control characters. An attacked could potentially exploit this to conduct

cross-site scripting (XSS) attacks.

Update Instructions

The problem can be corrected by updating your system to the following
package versions:

Ubuntu 14.04 LTS:
  python-lxml                     3.3.3-1ubuntu0.1
  python3-lxml                    3.3.3-1ubuntu0.1

Ubuntu 13.10:
  python-lxml                     3.2.0-1ubuntu0.1
  python3-lxml                    3.2.0-1ubuntu0.1

Ubuntu 12.04 LTS:
  python-lxml                     2.3.2-1ubuntu0.2
  python3-lxml                    2.3.2-1ubuntu0.2

After a standard system update you need to reboot your computer to make
all the necessary changes.

References

https://ubuntu.com/security/notices/USN-2217-1

CVE-2014-3146

May 21, 2014

Package Information

Get the latest News and Insights

Get the latest Linux and open source security news straight to your inbox.