Login
Newsletter
Werbung

Sicherheit: Denial of Service in Pygments
Aktuelle Meldungen Distributionen
Name: Denial of Service in Pygments
ID: USN-4885-1
Distribution: Ubuntu
Plattformen: Ubuntu 16.04 LTS, Ubuntu 18.04 LTS, Ubuntu 20.04 LTS, Ubuntu 20.10
Datum: Mo, 22. März 2021, 23:09
Referenzen: https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2021-20270
Applikationen: Pygments

Originalnachricht

This is an OpenPGP/MIME signed message (RFC 4880 and 3156)
--===============2343717225092885688==
Content-Type: multipart/signed; micalg=pgp-sha256;
protocol="application/pgp-signature";
boundary="7DrEuRliyLikemmZeZvSJTaX7wSfLt4Iu"

This is an OpenPGP/MIME signed message (RFC 4880 and 3156)
--7DrEuRliyLikemmZeZvSJTaX7wSfLt4Iu
Content-Type: multipart/mixed;
boundary="SrvC3xZqkz8cPyUiMBipUH35FLBY5ins8";
protected-headers="v1"
From: Marc Deslauriers <marc.deslauriers@canonical.com>
Reply-To: Ubuntu Security <security@ubuntu.com>
To: "ubuntu-security-announce@lists.ubuntu.com"
<ubuntu-security-announce@lists.ubuntu.com>
Message-ID: <a3f24103-fe9c-131b-dd85-fbcbba3f0a57@canonical.com>
Subject: [USN-4885-1] Pygments vulnerability

--SrvC3xZqkz8cPyUiMBipUH35FLBY5ins8
Content-Type: text/plain; charset=utf-8
Content-Language: en-C
Content-Transfer-Encoding: quoted-printable

==========================================================================
Ubuntu Security Notice USN-4885-1
March 22, 2021

pygments vulnerability
==========================================================================

A security issue affects these releases of Ubuntu and its derivatives:

- Ubuntu 20.10
- Ubuntu 20.04 LTS
- Ubuntu 18.04 LTS
- Ubuntu 16.04 LTS

Summary:

pygments could be made to hang if it opened a specially crafted file.

Software Description:
- pygments: Generic syntax highlighter

Details:

It was discovered that Pygments incorrectly handled parsing SML files. If a
user or automated system were tricked into parsing a specially crafted SML
file, a remote attacker could cause Pygments to hang, resulting in a denial
of service.

Update instructions:

The problem can be corrected by updating your system to the following
package versions:

Ubuntu 20.10:
python3-pygments 2.3.1+dfsg-4ubuntu0.1

Ubuntu 20.04 LTS:
python-pygments 2.3.1+dfsg-1ubuntu2.1
python3-pygments 2.3.1+dfsg-1ubuntu2.1

Ubuntu 18.04 LTS:
python-pygments 2.2.0+dfsg-1ubuntu0.1
python3-pygments 2.2.0+dfsg-1ubuntu0.1

Ubuntu 16.04 LTS:
python-pygments 2.1+dfsg-1ubuntu0.1
python3-pygments 2.1+dfsg-1ubuntu0.1

In general, a standard system update will make all the necessary changes.

References:
https://ubuntu.com/security/notices/USN-4885-1
CVE-2021-20270

Package Information:
https://launchpad.net/ubuntu/+source/pygments/2.3.1+dfsg-4ubuntu0.1
https://launchpad.net/ubuntu/+source/pygments/2.3.1+dfsg-1ubuntu2.1
https://launchpad.net/ubuntu/+source/pygments/2.2.0+dfsg-1ubuntu0.1
https://launchpad.net/ubuntu/+source/pygments/2.1+dfsg-1ubuntu0.1


--SrvC3xZqkz8cPyUiMBipUH35FLBY5ins8--

--7DrEuRliyLikemmZeZvSJTaX7wSfLt4Iu
Content-Type: application/pgp-signature; name="OpenPGP_signature.asc"
Content-Description: OpenPGP digital signature
Content-Disposition: attachment; filename="OpenPGP_signature"

-----BEGIN PGP SIGNATURE-----

iQIzBAEBCgAdFiEEUMSg3c8x5FLOsZtRZWnYVadEvpMFAmBYrD8ACgkQZWnYVadE
vpNkNQ/+MbQ4w/Op+ustQQL/0c2Dfmp1PFrvjk1sMX4TWHq1osm8D1gyIL/6PuXW
Nh0cN9Vo4nduhLS2v0leVcKb1USmcTvKzjgZc1jyvY/AarFM/mBsvejkJW/gCrZ3
+W2tgCcpMprvkskE3VB+jgKyU4s3dOW36oq80Hd1E8H49nFykgUPcmcnny9ROfIl
tEQEpKdGaE8uNa+OCYbvhpveiGYJW9tM+cLMeOJPw9fcU/vxrqiIRKGzuyPi+xzt
cVktq2uuGGZsQdWgEnwDXOuq5RG+mqjosv1YXuQ+sLOU9l/ypbG9QGpqzpWOJZsM
FdE/AMs6LV2wKyLGvSIdOJ7QVhyBufEsUUsALg/sKW5Ut9Q8s+qfyoR8uZK+H9Ju
0+gkek1+wzjZ/hgMNAw0hMvztwxncQp4k+FBic8N8GEdXxio+au9kMJUr8WcTfog
hE3eEs/dn4dSV85JGVrAgQ3nztVe+U4umg52OyH5LTdG2Y5Atet6eTOzBW7ZjGi9
BmqW9ZDs2/kTUHFzdpikv4iV+1zEdASrY4lSD+/K61g490Xht/6toox6oq8Gr5qE
UREmr0DBcIRM22WdQXtHNDEP7ZJ31QeWtauZ9dVXc8FjlZxdzMnDhEFd3cXrsbyJ
vVebR5KjKL7wnPhZq6ZBDgqzGFd1VEjs/V6Pe1Q+lP/hRsdPn9A=
=Hjmi
-----END PGP SIGNATURE-----

--7DrEuRliyLikemmZeZvSJTaX7wSfLt4Iu--


--===============2343717225092885688==
Content-Type: text/plain; charset="utf-8"
MIME-Version: 1.0
Content-Transfer-Encoding: base64
Content-Disposition: inline

LS0gCnVidW50dS1zZWN1cml0eS1hbm5vdW5jZSBtYWlsaW5nIGxpc3QKdWJ1bnR1LXNlY3VyaXR5
LWFubm91bmNlQGxpc3RzLnVidW50dS5jb20KTW9kaWZ5IHNldHRpbmdzIG9yIHVuc3Vic2NyaWJl
IGF0OiBodHRwczovL2xpc3RzLnVidW50dS5jb20vbWFpbG1hbi9saXN0aW5mby91YnVudHUtc2Vj
dXJpdHktYW5ub3VuY2UK

--===============2343717225092885688==--
Pro-Linux
Pro-Linux @Facebook
Neue Nachrichten
Werbung