--- lxml-3.5.0.orig/debian/changelog +++ lxml-3.5.0/debian/changelog @@ -0,0 +1,444 @@ +lxml (3.5.0-1ubuntu0.4) xenial-security; urgency=medium + + * SECURITY UPDATE: incorrect formaction attribute input sanitization + - Add HTML-5 formaction attribute to defs.link_attrs in + src/lxml/html/defs.py, src/lxml/html/tests/test_clean.py. + - CVE-2021-28957 + + -- Marc Deslauriers Mon, 29 Mar 2021 12:05:53 -0400 + +lxml (3.5.0-1ubuntu0.3) xenial-security; urgency=medium + + * SECURITY UPDATE: XSS vulnerability + - This adds the missing part reported from upstream + Prevent combinations of