OESA-2021-1154
Dashboard / Vulnerabilities / OESA-2021-1154
Summary: python-pygments security update
Details: Security Fix(es): In pygments 1.1+, fixed in 2.7.4, the lexers used to parse programming languages rely heavily on regular expressions. Some of the regular expressions have exponential or cubic worst-case complexity and are vulnerable to ReDoS. By crafting malicious input, an attacker can cause a denial of service.(CVE-2021-27291) An infinite loop in SMLLexer in Pygments versions 1.5 to 2.7.3 may lead to denial of service when performing syntax highlighting of a Standard ML (SML) source file, as demonstrated by input that only contains the "exception" keyword.(CVE-2021-20270)
References: https://openeuler.org/en/security/safety-bulletin/detail.html?id=openEuler-SA-2021-1154, https://nvd.nist.gov/vuln/detail/CVE-2021-27291, https://nvd.nist.gov/vuln/detail/CVE-2021-20270
Affected packages
Package
Name: python-pygments
Purl: pkg:rpm/openEuler/python-pygments&distro=openEuler-20.03-LTS-SP1
Affected ranges
Type: ECOSYSTEM
Events:
