{"id":"MGASA-2014-0218","summary":"Updated python-lxml package fix CVE-2014-3146","details":"Updated python-lxml packages fix security vulnerability:\n\nThe clean_html() function, provided by the lxml.html.clean module, did not\nproperly clean HTML input if it included non-printed characters (\\x01-\\x08).\nA remote attacker could use this flaw to serve malicious content to an\napplication using the clean_html() function to process HTML, possibly\nallowing the attacker to inject malicious code into a website generated by\nthis application (CVE-2014-3146).\n","modified":"2026-04-16T06:22:39.657038255Z","published":"2014-05-14T22:10:47Z","upstream":["CVE-2014-3146"],"references":[{"type":"ADVISORY","url":"https://advisories.mageia.org/MGASA-2014-0218.html"},{"type":"WEB","url":"https://lists.fedoraproject.org/pipermail/package-announce/2014-May/132472.html"},{"type":"REPORT","url":"https://bugs.mageia.org/show_bug.cgi?id=13326"}],"affected":[{"package":{"name":"python-lxml","ecosystem":"Mageia:3","purl":"pkg:rpm/mageia/python-lxml?arch=source&distro=mageia-3"},"ranges":[{"type":"ECOSYSTEM","events":[{"introduced":"0"},{"fixed":"3.0.1-2.1.mga3"}]}],"ecosystem_specific":{"section":"core"},"database_specific":{"source":"https://advisories.mageia.org/MGASA-2014-0218.json"}},{"package":{"name":"python-lxml","ecosystem":"Mageia:4","purl":"pkg:rpm/mageia/python-lxml?arch=source&distro=mageia-4"},"ranges":[{"type":"ECOSYSTEM","events":[{"introduced":"0"},{"fixed":"3.2.4-1.1.mga4"}]}],"ecosystem_specific":{"section":"core"},"database_specific":{"source":"https://advisories.mageia.org/MGASA-2014-0218.json"}}],"schema_version":"1.7.5","credits":[{"name":"Mageia","contact":["https://wiki.mageia.org/en/Packages_Security_Team"],"type":"COORDINATOR"}]}