4.6.5 (2021-12-12) ================== Bugs fixed ---------- * A vulnerability (GHSL-2021-1038) in the HTML cleaner allowed sneaking script content through SVG images. * A vulnerability (GHSL-2021-1037) in the HTML cleaner allowed sneaking script content through CSS imports and other crafted constructs.
The bug has been referenced in the following commit(s): https://gitweb.gentoo.org/repo/gentoo.git/commit/?id=41eaacb18bc5b898691a20acf9c58659716642a2 commit 41eaacb18bc5b898691a20acf9c58659716642a2 Author: Arthur Zamarin <arthurzam@gentoo.org> AuthorDate: 2021-12-13 15:32:26 +0000 Commit: Arthur Zamarin <arthurzam@gentoo.org> CommitDate: 2021-12-13 15:33:25 +0000 dev-python/lxml: drop 4.6.4 Bug: https://bugs.gentoo.org/829053 Signed-off-by: Arthur Zamarin <arthurzam@gentoo.org> dev-python/lxml/Manifest | 1 - dev-python/lxml/lxml-4.6.4.ebuild | 97 --------------------------------------- 2 files changed, 98 deletions(-)
Thank you!
GLSA request filed.
The bug has been referenced in the following commit(s): https://gitweb.gentoo.org/data/glsa.git/commit/?id=00cb8ca9acda9480b2cbc77e709e6f1c6d0babf4 commit 00cb8ca9acda9480b2cbc77e709e6f1c6d0babf4 Author: GLSAMaker <glsamaker@gentoo.org> AuthorDate: 2022-08-10 03:53:32 +0000 Commit: John Helmert III <ajak@gentoo.org> CommitDate: 2022-08-10 04:16:21 +0000 [ GLSA 202208-06 ] lxml: Multiple Vulnerabilities Bug: https://bugs.gentoo.org/777579 Bug: https://bugs.gentoo.org/829053 Bug: https://bugs.gentoo.org/856598 Signed-off-by: GLSAMaker <glsamaker@gentoo.org> Signed-off-by: John Helmert III <ajak@gentoo.org> glsa-202208-06.xml | 48 ++++++++++++++++++++++++++++++++++++++++++++++++ 1 file changed, 48 insertions(+)
GLSA released, all done!