-----BEGIN PGP SIGNED MESSAGE----- Hash: SHA256 Format: 1.8 Date: Mon, 22 Mar 2021 14:31:55 +0100 Source: lxml Architecture: source Version: 4.6.3-1 Distribution: unstable Urgency: high Maintainer: Matthias Klose <doko@debian.org> Changed-By: Matthias Klose <doko@debian.org> Changes: lxml (4.6.3-1) unstable; urgency=high . * New upstream version. - A vulnerability (CVE-2021-28957) was discovered in the HTML Cleaner, which allowed JavaScript to pass through. The cleaner now removes the HTML5 formaction attribute. Checksums-Sha1: 73141b3a5db37fb89981bd2679e4851e974b0a1a 2026 lxml_4.6.3-1.dsc 83e7798d0d2c74c9a5e087211e972a3d0e157cee 948931 lxml_4.6.3.orig.tar.gz 350cb05de778c75aa7c54822f85ac99b1b09970f 7580 lxml_4.6.3-1.debian.tar.xz e0d40d18f28390ab5cd36197f00bb8b4584fc0f0 7430 lxml_4.6.3-1_source.buildinfo Checksums-Sha256: 28a0c0c46cfae8c5efc509b0374d3fd74b476fe430e8532163173eab148cdec3 2026 lxml_4.6.3-1.dsc 5955ed615b7be9407d9eab83edde8f1818c94224d762d1d6355bf0371f220bd6 948931 lxml_4.6.3.orig.tar.gz 3e2e520de0956da3549019171209bf50ae42ddf5da53ea4a3707e5eabbf75345 7580 lxml_4.6.3-1.debian.tar.xz 50d453f995dbed8015e884920ed366266cbf051106c7b9c0de722db8eb4ff01d 7430 lxml_4.6.3-1_source.buildinfo Files: 55010a1bc010c7a866a782ebeba8e9b0 2026 python optional lxml_4.6.3-1.dsc fd1267d952ea185db8018afe33b4895d 948931 python optional lxml_4.6.3.orig.tar.gz dd00a14eea781d31db9d23e99bb6a036 7580 python optional lxml_4.6.3-1.debian.tar.xz d7790b46f85fbe0cc990c35550c160c8 7430 python optional lxml_4.6.3-1_source.buildinfo -----BEGIN PGP SIGNATURE----- iQJEBAEBCAAuFiEE1WVxuIqLuvFAv2PWvX6qYHePpvUFAmBYnMwQHGRva29AZGVi aWFuLm9yZwAKCRC9fqpgd4+m9eGXD/9jktwyy1FUodNBN8pnnmTAP+QPspIxHkVa jtBNDqh0bYzxE8LNU/14fzhQQ7Jnkqr6jLbAEW7zwVIy995H1csrRbt/r19CAPDe S5XG+5hrBZofwg7LkPDfMst+65h8mi4J2cHg3iPGlHrPrYel8DTrqJhBD/Eylrgu CydeSdV7Y3G+k9EhRXxjZ3ERRFjAMjcf4sFwr7+NgcdptY+AG5YSmeUao+yJi7fy WqDszXH5lABv3FDcxXA4qQQ8QcZmPL3GIwFmV7PWHt48q88HK23mP5+BR4rEzDDh wasIKxUip7edi4S0AETaXlvsrv1cXrJKfTITUCC1RVrayV++4ZJ4R6VA8sfmudGw 7Ps+a0HDwLv99/LmXnKkAM719V3no7d/swVD0Hqpbmh9L0eAbhpshar189YYm/Eu LPFvjuyvsR0x2gkk2pD1stk9/lO9j/++DlDQKmdy9PL3ZC8tOCusZDoouLGC9LvC mLhqJVXvDcVH83UyprtfNz1jAWros3bcVvX81Ne7KbuCPdTNMFKZGVp5vsKfTmfv RPC9AmJF4bHIOipiGmRTcZFRhmR10uSlx5reZVferosT19IPs4WDowKcXJXOH6Zt lBf19t+CS71mqVcTh70ZNlSuWeuKljecTRnGOZigtCVwFpMyshFDCdN1kGTQcWqP MszpkPn1QA== =CxKi -----END PGP SIGNATURE-----