Univention Bugzilla – Bug 52531
lxml: Multiple issues (4.4)
Last modified: 2021-01-06 16:53:48 CET
New Debian lxml 3.7.1-1+deb9u3 fixes: This update addresses the following issue: * CVE-2020-27783: Backport additional upstream commit a105ab8dc262ec6735977c25c13f0bdfcdec72a7 to address math/svg part of the vulnerability and complete the fix
--- mirror/ftp/4.4/unmaintained/component/4.4-7-errata/source/lxml_3.7.1-1+deb9u1.dsc +++ apt/ucs_4.4-0-errata4.4-7/source/lxml_3.7.1-1+deb9u3.dsc @@ -1,3 +1,19 @@ +3.7.1-1+deb9u3 [Fri, 18 Dec 2020 09:50:10 +0100] Emilio Pozuelo Monfort <pochu@debian.org>: + + * Non-maintainer upload by the LTS Team. + * Enable the test suite (non-fatal). + * Switch to source format 3.0 (quilt), rather than having the patches + in debian/patches/ but applied directly without a patch system. + * Fix regression in Python 2 in the last part of CVE-2020-27783. + * math-svg.patch: update expected results for the test suite. + +3.7.1-1+deb9u2 [Tue, 15 Dec 2020 13:23:34 -0500] Roberto C. Sánchez <roberto@debian.org>: + + * Non-maintainer upload by the LTS Team. + * CVE-2020-27783: Backport additional upstream commit + a105ab8dc262ec6735977c25c13f0bdfcdec72a7 to address math/svg part of the + vulnerability and complete the fix + 3.7.1-1+deb9u1 [Thu, 26 Nov 2020 18:38:23 +0530] Abhijith PA <abhijith@debian.org>: * Non-maintainer upload by the Debian LTS Team. <http://10.200.17.11/4.4-7/#5622458748675860778>
OK: yaml OK: announce_errata OK: patch OK: piuparts [4.4-7] 12153e8fd6 Bug #52531: lxml_3.7.1-1+deb9u3 doc/errata/staging/lxml.yaml | 14 ++++++++++++++ 1 file changed, 14 insertions(+)
<https://errata.software-univention.de/#/?erratum=4.4x854>