MGASA-2021-0245
Dashboard / Vulnerabilities / MGASA-2021-0245
Summary: Updated python-pygments packages fix a security vulnerability
Details: In pygments 1.1+, fixed in 2.7.4, the lexers used to parse programming languages rely heavily on regular expressions. Some of the regular expressions have exponential or cubic worst-case complexity and are vulnerable to ReDoS. By crafting malicious input, an attacker can cause a denial of service (CVE-2021-27291).
References: https://advisories.mageia.org/MGASA-2021-0245.html, https://bugs.mageia.org/show_bug.cgi?id=28982, https://lists.fedoraproject.org/archives/list/[email protected]/thread/GSJRFHALQ7E3UV4FFMFU2YQ6LUDHAI55/
Affected packages
Package
Name: python-pygments
Purl: pkg:rpm/mageia/python-pygments?arch=source&distro=mageia-7
Affected ranges
Type: ECOSYSTEM
Events:
