oss-sec mailing list archives

CVE request for python-feedparser


From: Vincent Danen <vdanen () redhat com>
Date: Mon, 14 Mar 2011 11:16:21 -0600

python-feedparser 5.0.1 fixes three flaws:

https://code.google.com/p/feedparser/

* Fix  issue 91  (invalid text in XML declaration causes sanitizer to crash)
* Fix  issue 254  (sanitization can be bypassed by malformed XML comments)
* Fix issue 255 (sanitizer doesn't strip unsafe URI schemes)
Could CVE names be assigned to these issues?

It looks like the last two issues were introduced in 5.0, the first
issue was reported against 4.1.

Thanks.

--
Vincent Danen / Red Hat Security Response Team

Current thread: