CVE-2014-3146

NameCVE-2014-3146
DescriptionIncomplete blacklist vulnerability in the lxml.html.clean module in lxml before 3.3.5 allows remote attackers to conduct cross-site scripting (XSS) attacks via control characters in the link scheme to the clean_html function.
SourceCVE (at NVD; oss-sec, fulldisc, OSVDB, EDB, Metasploit, Red Hat, Ubuntu, Gentoo, SuSE, Mageia, more)
ReferencesDLA-0009-1, DSA-2941-1
NVD severitymedium (attack range: remote, user-initiated)
Debian Bugs746812
Debian/oldstablepackage lxml is vulnerable.
Debian/stablenot vulnerable.
Debian/testingnot vulnerable.
Debian/unstablenot vulnerable.

Vulnerable and fixed packages

The table below lists information on source packages.

Source PackageReleaseVersionStatus
lxml (PTS)squeeze2.2.8-2vulnerable
squeeze (lts)2.2.8-2+deb6u1fixed
wheezy, wheezy (security)2.3.2-1+deb7u1fixed
jessie3.4.0-1fixed
sid3.4.2-1fixed

The information above is based on the following data on fixed versions.

PackageTypeReleaseFixed VersionUrgencyOriginDebian Bugs
lxmlsource(unstable)3.3.5-1medium746812
lxmlsourcesqueeze2.2.8-2+deb6u1medium
lxmlsourcewheezy2.3.2-1+deb7u1mediumDSA-2941-1

Notes

http://lxml.de/3.3/changes-3.3.5.html
http://seclists.org/fulldisclosure/2014/Apr/210
https://github.com/lxml/lxml/commit/e86b294f1f81b899a59925123560ff924a72f1cc

Search for package or bug name: Reporting problems