Back to lxml PTS page

Accepted lxml 4.6.3-1 (source) into unstable



-----BEGIN PGP SIGNED MESSAGE-----
Hash: SHA256

Format: 1.8
Date: Mon, 22 Mar 2021 14:31:55 +0100
Source: lxml
Architecture: source
Version: 4.6.3-1
Distribution: unstable
Urgency: high
Maintainer: Matthias Klose <doko@debian.org>
Changed-By: Matthias Klose <doko@debian.org>
Changes:
 lxml (4.6.3-1) unstable; urgency=high
 .
   * New upstream version.
     - A vulnerability (CVE-2021-28957) was discovered in the HTML Cleaner,
       which allowed JavaScript to pass through. The cleaner now removes the
       HTML5 formaction attribute.
Checksums-Sha1:
 73141b3a5db37fb89981bd2679e4851e974b0a1a 2026 lxml_4.6.3-1.dsc
 83e7798d0d2c74c9a5e087211e972a3d0e157cee 948931 lxml_4.6.3.orig.tar.gz
 350cb05de778c75aa7c54822f85ac99b1b09970f 7580 lxml_4.6.3-1.debian.tar.xz
 e0d40d18f28390ab5cd36197f00bb8b4584fc0f0 7430 lxml_4.6.3-1_source.buildinfo
Checksums-Sha256:
 28a0c0c46cfae8c5efc509b0374d3fd74b476fe430e8532163173eab148cdec3 2026 lxml_4.6.3-1.dsc
 5955ed615b7be9407d9eab83edde8f1818c94224d762d1d6355bf0371f220bd6 948931 lxml_4.6.3.orig.tar.gz
 3e2e520de0956da3549019171209bf50ae42ddf5da53ea4a3707e5eabbf75345 7580 lxml_4.6.3-1.debian.tar.xz
 50d453f995dbed8015e884920ed366266cbf051106c7b9c0de722db8eb4ff01d 7430 lxml_4.6.3-1_source.buildinfo
Files:
 55010a1bc010c7a866a782ebeba8e9b0 2026 python optional lxml_4.6.3-1.dsc
 fd1267d952ea185db8018afe33b4895d 948931 python optional lxml_4.6.3.orig.tar.gz
 dd00a14eea781d31db9d23e99bb6a036 7580 python optional lxml_4.6.3-1.debian.tar.xz
 d7790b46f85fbe0cc990c35550c160c8 7430 python optional lxml_4.6.3-1_source.buildinfo

-----BEGIN PGP SIGNATURE-----

iQJEBAEBCAAuFiEE1WVxuIqLuvFAv2PWvX6qYHePpvUFAmBYnMwQHGRva29AZGVi
aWFuLm9yZwAKCRC9fqpgd4+m9eGXD/9jktwyy1FUodNBN8pnnmTAP+QPspIxHkVa
jtBNDqh0bYzxE8LNU/14fzhQQ7Jnkqr6jLbAEW7zwVIy995H1csrRbt/r19CAPDe
S5XG+5hrBZofwg7LkPDfMst+65h8mi4J2cHg3iPGlHrPrYel8DTrqJhBD/Eylrgu
CydeSdV7Y3G+k9EhRXxjZ3ERRFjAMjcf4sFwr7+NgcdptY+AG5YSmeUao+yJi7fy
WqDszXH5lABv3FDcxXA4qQQ8QcZmPL3GIwFmV7PWHt48q88HK23mP5+BR4rEzDDh
wasIKxUip7edi4S0AETaXlvsrv1cXrJKfTITUCC1RVrayV++4ZJ4R6VA8sfmudGw
7Ps+a0HDwLv99/LmXnKkAM719V3no7d/swVD0Hqpbmh9L0eAbhpshar189YYm/Eu
LPFvjuyvsR0x2gkk2pD1stk9/lO9j/++DlDQKmdy9PL3ZC8tOCusZDoouLGC9LvC
mLhqJVXvDcVH83UyprtfNz1jAWros3bcVvX81Ne7KbuCPdTNMFKZGVp5vsKfTmfv
RPC9AmJF4bHIOipiGmRTcZFRhmR10uSlx5reZVferosT19IPs4WDowKcXJXOH6Zt
lBf19t+CS71mqVcTh70ZNlSuWeuKljecTRnGOZigtCVwFpMyshFDCdN1kGTQcWqP
MszpkPn1QA==
=CxKi
-----END PGP SIGNATURE-----