| Summary: | python-html5lib new security issues CVE-2016-9909 and CVE-2016-9910 | ||
|---|---|---|---|
| Product: | Mageia | Reporter: | David Walser <luigiwalser> |
| Component: | Security | Assignee: | QA Team <qa-bugs> |
| Status: | RESOLVED FIXED | QA Contact: | Sec team <security> |
| Severity: | normal | ||
| Priority: | Normal | CC: | herman.viaene, lewyssmith, shlomif, sysadmin-bugs |
| Version: | 5 | Keywords: | validated_update |
| Target Milestone: | --- | ||
| Hardware: | All | ||
| OS: | Linux | ||
| URL: | https://lwn.net/Vulnerabilities/709146/ | ||
| Whiteboard: | MGA5-32-OK advisory MGA5-64-OK | ||
| Source RPM: | python-html5lib-1.0b8-2.mga6.src.rpm | CVE: | CVE-2016-9909 and CVE-2016-9910 |
| Status comment: | |||
|
Description
David Walser
2016-12-08 15:32:22 CET
David Walser
2016-12-08 15:32:46 CET
CC:
(none) =>
shlomif Freeze push asked for Cauldron, for Mga5, I'll try, but that's not a major security issue. python-html5lib-1.0b3-7.1.mga5.noarch python3-html5lib-1.0b3-7.1.mga5.noarch From python-html5lib-1.0b3-7.1.mga5.src.rpm Are in core/updates_testing Fix potential cross-site scripting vulnerablity: quote attributes that need escaping in legacy browsers. Ref : http://www.openwall.com/lists/oss-security/2016/12/08/8 https://github.com/html5lib/html5lib-python/issues/11 https://github.com/html5lib/html5lib-python/issues/12 http://www.cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2014-9909 http://www.cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2014-9910 For testers : package have a test section for both python2 and python3 that is run during build : Ran 21566 tests in 29.301s Ran 21566 tests in 35.569s So I guess that a simple update is enough. CVE:
(none) =>
CVE-2016-9909 and CVE-2016-9910
David Walser
2016-12-10 17:13:18 CET
Version:
Cauldron =>
5
David Walser
2016-12-14 18:17:42 CET
URL:
(none) =>
https://lwn.net/Vulnerabilities/709146/ MGA5-32 on Acer D620 Xfce No installation issues - OK CC:
(none) =>
herman.viaene Advisory from Comment 2 uploaded. CC:
(none) =>
lewyssmith Testing M5 x64 I could find no previous bug for this package; so following the handy advice in Comment 2 (thanks Philippe), I just installed from current repos: python-html5lib-1.0b3-7.mga5.noarch.rpm then updated it from Updates Testing to: python-html5lib-1.0b3-7.1.mga5 No problems => OK! Validating; advisory already in place. Keywords:
(none) =>
validated_update An update for this issue has been pushed to the Mageia Updates repository. http://advisories.mageia.org/MGASA-2017-0001.html Status:
NEW =>
RESOLVED |