USN-3841-1: lxml vulnerability
Published Dec 10, 2018
·Updated
It was discovered that lxml incorrectly handled certain HTML files. An attacker could possibly use this issue to conduct cross-site scripting (XSS) attacks.
Affected Software
1 affected component
pypi/lxml
Event History
Dec 31, 2025
Advisory Published
via Ubuntu·03:39 PM
Data Sourced
via Ubuntu·03:39 PM
DescriptionAffected Software
Frequently Asked Questions
1
What is the vulnerability ID of this issue?
The vulnerability ID is USN-3841-1.
2
What is the severity of the USN-3841-1 vulnerability?
The severity of the USN-3841-1 vulnerability is not specified in the information provided.
3
How does the USN-3841-1 vulnerability affect the software?
The USN-3841-1 vulnerability affects the lxml library in Ubuntu 14.04, 16.04, and 18.04.
4
How can an attacker exploit the USN-3841-1 vulnerability?
An attacker can exploit the USN-3841-1 vulnerability by using specially crafted HTML files to conduct cross-site scripting (XSS) attacks.
5
How can I fix the USN-3841-1 vulnerability?
To fix the USN-3841-1 vulnerability, update to version 4.2.1-1ubuntu0.1 for python-lxml or python3-lxml on Ubuntu 14.04, 16.04, or 18.04.