Upstream information
Description
Cross-site scripting (XSS) vulnerability in feedparser.py in Universal Feed Parser (aka feedparser or python-feedparser) before 5.0 allows remote attackers to inject arbitrary web script or HTML via vectors involving nested CDATA stanzas.NVD CVSS v2 Base Score: 4.3 (AV:N/AC:M/Au:N/C:N/I:P/A:N)
Novell/SUSE information
Novell Bugzilla entry: 680074 SUSE Security Advisories:- SUSE-SR:2011:007, published Tue, 19 Apr 2011 12:00:00 +0000
- openSUSE-SU-2011:0314-1, published Fri, 8 Apr 2011 13:08:37 +0200 (CEST)
List of released packages
| Product(s) | Fixed package version(s) | References |
|---|---|---|
| openSUSE 11.2 |
| |
| openSUSE 11.3 |
| |
| openSUSE 11.4 |
|
