Author: renodr
Date: Tue Dec 1 13:16:28 2020
New Revision: 1647
Log:
Errata: update errata for lxml
Modified:
html/trunk/blfs/errata/10.0-systemd/index.html
html/trunk/blfs/errata/10.0/index.html
Modified: html/trunk/blfs/errata/10.0-systemd/index.html
==============================================================================
--- html/trunk/blfs/errata/10.0-systemd/index.html Thu Nov 26 12:16:44
2020 (r1646)
+++ html/trunk/blfs/errata/10.0-systemd/index.html Tue Dec 1 13:16:28
2020 (r1647)
@@ -146,11 +146,11 @@
This issue had to do with the 'redirect' option. To fix this issue,
update to stunnel-5.57 or later using the instructions in
<a
href="../../view/systemd/postlfs/stunnel.html">stunnel-5.57</a>.</li>
- <li>After release, a security issue was discovered in lxml that allowed
+ <li>After release, two security issues were discovered in lxml that
allowed
it to process JavaScript code. This could potentially lead to
arbitrary code execution. To fix this vulnerability, update to
- lxml-4.6.1 or later using the instructions in
- <a
href="../../view/systemd/general/python-modules.html#lxml">lxml-4.6.1</a>.</li>
+ lxml-4.6.2 or later using the instructions in
+ <a
href="../../view/systemd/general/python-modules.html#lxml">lxml-4.6.2</a>.</li>
<li>After release, a security vulnerability was discovered in freetype
(all versions since 2.6), a buffer overflow when processing TTF
files
which include PNG glyphs - this is being actively used in the wild.
Modified: html/trunk/blfs/errata/10.0/index.html
==============================================================================
--- html/trunk/blfs/errata/10.0/index.html Thu Nov 26 12:16:44 2020
(r1646)
+++ html/trunk/blfs/errata/10.0/index.html Tue Dec 1 13:16:28 2020
(r1647)
@@ -144,11 +144,11 @@
This issue had to do with the 'redirect' option. To fix this issue,
update to stunnel-5.57 or later using the instructions in
<a href="../../view/svn/postlfs/stunnel.html">stunnel-5.57</a>.</li>
- <li>After release, a security issue was discovered in lxml that allowed
+ <li>After release, two security issues were discovered in lxml that
allowed
it to process JavaScript code. This could potentially lead to
arbitrary code execution. To fix this vulnerability, update to
- lxml-4.6.1 or later using the instructions in
- <a
href="../../view/svn/general/python-modules.html#lxml">lxml-4.6.1</a>.</li>
+ lxml-4.6.2 or later using the instructions in
+ <a
href="../../view/svn/general/python-modules.html#lxml">lxml-4.6.2</a>.</li>
<li>After release, a security vulnerability was discovered in freetype
(all versions since 2.6), a buffer overflow when processing TTF
files
which include PNG glyphs - this is being actively used in the wild.
--
http://lists.linuxfromscratch.org/listinfo/website
FAQ: http://www.linuxfromscratch.org/blfs/faq.html
Unsubscribe: See the above information page