QID 198314

Date Published: 2021-04-06

QID 198314: Ubuntu Security Notification for Lxml Vulnerability (USN-4896-1)

It was discovered that lxml incorrectly handled certain HTML attributes.

A remote attacker could possibly use this issue to perform cross-site scripting (XSS) attacks.

  • CVSS V3 rated as High - 6.1 severity.
  • CVSS V2 rated as Medium - 4.3 severity.
  • Solution
    Refer to Ubuntu advisory USN-4896-1 for affected packages and patching details, or update with your package manager.
    Vendor References

    CVEs related to QID 198314

    Software Advisories
    Advisory ID Software Component Link
    USN-4896-1 16.04 (Xenial) on src python-lxml URL Logo launchpad.net/ubuntu/+source/lxml/3.5.0-1ubuntu0.4
    USN-4896-1 16.04 (Xenial) on src python3-lxml URL Logo launchpad.net/ubuntu/+source/lxml/3.5.0-1ubuntu0.4
    USN-4896-1 18.04 (bionic) on src python-lxml URL Logo launchpad.net/ubuntu/+source/lxml/4.2.1-1ubuntu0.4
    USN-4896-1 18.04 (bionic) on src python3-lxml URL Logo launchpad.net/ubuntu/+source/lxml/4.2.1-1ubuntu0.4
    USN-4896-1 20.04 (focal) on src python-lxml URL Logo launchpad.net/ubuntu/+source/lxml/4.5.0-1ubuntu0.3
    USN-4896-1 20.04 (focal) on src python3-lxml URL Logo launchpad.net/ubuntu/+source/lxml/4.5.0-1ubuntu0.3
    USN-4896-1 20.10 (groovy) on src python3-lxml URL Logo launchpad.net/ubuntu/+source/lxml/4.5.2-1ubuntu0.4