[Python-modules-team] Bug#892252: src:python-bleach: URI values with character entities not properly sanitized

2018-03-07 Thread Salvatore Bonaccorso
Control: retitle -1 python-bleach: CVE-2018-7753: URI values with character entities not properly sanitized Hi Scott, On Wed, Mar 07, 2018 at 02:09:14AM -0500, Scott Kitterman wrote: > Package: src:python-bleach > Version: 2.1.2-1 > Severity: important > Tags: upstream, security > > > Version

[Python-modules-team] Bug#892252: src:python-bleach: URI values with character entities not properly sanitized

2018-03-06 Thread Scott Kitterman
Package: src:python-bleach Version: 2.1.2-1 Severity: important Tags: upstream, security Version 2.1.3 (March 5th, 2018) --- **Security fixes** * Attributes that have URI values weren't properly sanitized if the values contained character entities. Using character