Overly broad permissions can turn one compromised account into a much larger security problem. Learn how to reduce unnecessary access, review privileges, and apply least privilege across modern Linux systems. Review Linux Privileges×
Update the ammonia crate to version 3.3.1 and rebuild python-nh3 to apply fixes for RUSTSEC-2025-0071.. -------------------------------------------------------------------------------- Fedora Update Notification FEDORA-2025-1be5992b52 2025-10-01 15:00:59.894553+00:00 -------------------------------------------------------------------------------- Name : rust-ammonia Product : Fedora 41 Version : 3.3.1 Release : 1.fc41 URL : https://crates.io/crates/ammonia Summary : HTML Sanitization Description : HTML Sanitization. -------------------------------------------------------------------------------- Update Information: Update the ammonia crate to version 3.3.1 and rebuild python-nh3 to apply fixes for RUSTSEC-2025-0071. -------------------------------------------------------------------------------- ChangeLog: * Mon Sep 22 2025 Fabio Valentini - 3.3.1-1 - Update to version 3.3.1 -------------------------------------------------------------------------------- This update can be installed with the "dnf" update program. Use su -c 'dnf upgrade --advisory FEDORA-2025-1be5992b52' at the command line. For more information, refer to the dnf documentation available at http://dnf.readthedocs.io/en/latest/command_ref.html#upgrade-command-label All packages are signed with the Fedora Project GPG key. More details on the GPG keys used by the Fedora Project can be found at https://fedoraproject.org/keys -------------------------------------------------------------------------------- -- _______________________________________________ package-announce mailing list --
Update the ammonia crate to version 4.0.1 and rebuild python-nh3 to apply fixes for RUSTSEC-2025-0071.. -------------------------------------------------------------------------------- Fedora Update Notification FEDORA-2025-7ec84ba6e9 2025-10-01 14:43:51.750497+00:00 -------------------------------------------------------------------------------- Name : rust-ammonia Product : Fedora 42 Version : 4.0.1 Release : 1.fc42 URL : https://crates.io/crates/ammonia Summary : HTML Sanitization Description : HTML Sanitization. -------------------------------------------------------------------------------- Update Information: Update the ammonia crate to version 4.0.1 and rebuild python-nh3 to apply fixes for RUSTSEC-2025-0071. -------------------------------------------------------------------------------- ChangeLog: * Mon Sep 22 2025 Fabio Valentini - 4.0.1-1 - Update to version 4.0.1 -------------------------------------------------------------------------------- This update can be installed with the "dnf" update program. Use su -c 'dnf upgrade --advisory FEDORA-2025-7ec84ba6e9' at the command line. For more information, refer to the dnf documentation available at http://dnf.readthedocs.io/en/latest/command_ref.html#upgrade-command-label All packages are signed with the Fedora Project GPG key. More details on the GPG keys used by the Fedora Project can be found at https://fedoraproject.org/keys -------------------------------------------------------------------------------- -- _______________________________________________ package-announce mailing list --
Update the ammonia crate to version 4.1.2 and rebuild python-nh3 to apply fixes for RUSTSEC-2025-0071.. -------------------------------------------------------------------------------- Fedora Update Notification FEDORA-2025-074aba6ad4 2025-10-01 00:14:58.043372+00:00 -------------------------------------------------------------------------------- Name : rust-ammonia Product : Fedora 43 Version : 4.1.2 Release : 1.fc43 URL : https://crates.io/crates/ammonia Summary : HTML Sanitization Description : HTML Sanitization. -------------------------------------------------------------------------------- Update Information: Update the ammonia crate to version 4.1.2 and rebuild python-nh3 to apply fixes for RUSTSEC-2025-0071. -------------------------------------------------------------------------------- ChangeLog: * Mon Sep 22 2025 Fabio Valentini - 4.1.2-1 - Update to version 4.1.2; Fixes RHBZ#2397219 -------------------------------------------------------------------------------- References: [ 1 ] Bug #2396811 - python-nh3: Please rebuild in Fedora 43 https://bugzilla.redhat.com/show_bug.cgi?id=2396811 -------------------------------------------------------------------------------- This update can be installed with the "dnf" update program. Use su -c 'dnf upgrade --advisory FEDORA-2025-074aba6ad4' at the command line. For more information, refer to the dnf documentation available at http://dnf.readthedocs.io/en/latest/command_ref.html#upgrade-command-label All packages are signed with the Fedora Project GPG key. More details on the GPG keys used by the Fedora Project can be found at https://fedoraproject.org/keys -------------------------------------------------------------------------------- -- _______________________________________________ package-announce mailing list --
It was reported that python-bleach, a whitelist-based HTML-sanitizing library, is prone to a mutation XSS vulnerability in bleach.clean when "svg" or "math" are in the allowed tags, 'p' or "br" are in allowed tags, "style", "title", "noscript", "script", "textarea", "noframes", "iframe", or "xmp" are in allowed tags and 'strip_comments=False' is set (CVE-2021-23980). . MGASA-2021-0260 - Updated python-bleach packages fix a security vulnerability Publication date: 16 Jun 2021 URL: https://advisories.mageia.org/MGASA-2021-0260.html Type: security Affected Mageia releases: 7, 8 CVE: CVE-2021-23980 It was reported that python-bleach, a whitelist-based HTML-sanitizing library, is prone to a mutation XSS vulnerability in bleach.clean when "svg" or "math" are in the allowed tags, 'p' or "br" are in allowed tags, "style", "title", "noscript", "script", "textarea", "noframes", "iframe", or "xmp" are in allowed tags and 'strip_comments=False' is set (CVE-2021-23980). References: - https://bugs.mageia.org/show_bug.cgi?id=28986 - https://lists.debian.org/debian-security-announce/2021/msg00073.html - https://github.com/mozilla/bleach/security/advisories/GHSA-vv2x-vrpj-qqpq - - https://www.cve.org/CVERecord?id=CVE-2021-23980 SRPMS: - 7/core/python-bleach-3.1.4-1.1.mga7 - 8/core/python-bleach-3.3.0-1.mga8 . Recent patches to python-bleach tackle a critical XSS vulnerability impacting permitted tags; vital for safeguarding web applications on Mageia.. Python Bleach Update, HTML Sanitization, Mageia Security. . LinuxSecurity.com Team
It was reported that python-bleach, a whitelist-based HTML-sanitizing library, is prone to a mutation XSS vulnerability in bleach.clean when 'svg' or 'math' are in the allowed tags, 'p' or 'br' are in allowed tags, 'style', 'title', 'noscript', 'script', 'textarea', 'noframes', . - ------------------------------------------------------------------------- Debian Security Advisory DSA-4892-1
Michal Bentkowski discovered that ruby-sanitize, a whitelist-based HTML sanitizer, is prone to a HTML sanitization bypass vulnerability when using the "relaxed" or a custom config allowing certain elements. Content in a or element may not be sanitized correctly even . - ------------------------------------------------------------------------- Debian Security Advisory DSA-4730-1
An update that fixes one vulnerability is now available. . SUSE Security Update: Security update for rubygem-loofah ______________________________________________________________________________ Announcement ID: SUSE-SU-2019:2209-1 Rating: moderate References: #1086598 Cross-References: CVE-2018-8048 Affected Products: SUSE OpenStack Cloud Crowbar 9 SUSE OpenStack Cloud Crowbar 8 SUSE OpenStack Cloud 7 SUSE Enterprise Storage 4 ______________________________________________________________________________ An update that fixes one vulnerability is now available. Description: This update for rubygem-loofah fixes the following issues: - Security issue fixed: - CVE-2018-8048: Update fix to make Loofah::HTML5::Scrub.force_correct_attribute_escaping! callable from other gems (bsc#1086598). Patch Instructions: To install this SUSE Security Update use the SUSE recommended installation methods like YaST online_update or "zypper patch". Alternatively you can run the command listed for your product: - SUSE OpenStack Cloud Crowbar 9: zypper in -t patch SUSE-OpenStack-Cloud-Crowbar-9-2019-2209=1 - SUSE OpenStack Cloud Crowbar 8: zypper in -t patch SUSE-OpenStack-Cloud-Crowbar-8-2019-2209=1 - SUSE OpenStack Cloud 7: zypper in -t patch SUSE-OpenStack-Cloud-7-2019-2209=1 - SUSE Enterprise Storage 4: zypper in -t patch SUSE-Storage-4-2019-2209=1 Package List: - SUSE OpenStack Cloud Crowbar 9 (x86_64): ruby2.1-rubygem-loofah-2.0.2-3.8.1 - SUSE OpenStack Cloud Crowbar 8 (x86_64): ruby2.1-rubygem-loofah-2.0.2-3.8.1 - SUSE OpenStack Cloud 7 (aarch64 s390x x86_64): ruby2.1-rubygem-loofah-2.0.2-3.8.1 - SUSE Enterprise Storage 4 (aarch64 x86_64): ruby2.1-rubygem-loofah-2.0.2-3.8.1 References: https://www.suse.com/security/cve/CVE-2018-8048.html https://bugzilla.suse.com/1086598 _______________________________________________ sle-security-updates mailing list
It was discovered that ruby-loofah, a general library for manipulating and transforming HTML/XML documents and fragments, performed insufficient sanitising of SVG elements. . -----BEGIN PGP SIGNED MESSAGE----- Hash: SHA512 - ------------------------------------------------------------------------- Debian Security Advisory DSA-4364-1
Get the latest Linux and open source security news straight to your inbox.