Login
Newsletter
Werbung

Sicherheit: Denial of Service in Pygments
Aktuelle Meldungen Distributionen
Name: Denial of Service in Pygments
ID: USN-4897-1
Distribution: Ubuntu
Plattformen: Ubuntu 16.04 LTS, Ubuntu 18.04 LTS, Ubuntu 20.04 LTS, Ubuntu 20.10
Datum: Di, 30. März 2021, 23:00
Referenzen: https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2021-27291
Applikationen: Pygments

Originalnachricht

This is an OpenPGP/MIME signed message (RFC 4880 and 3156)
--===============0087223769808489116==
Content-Type: multipart/signed; micalg=pgp-sha256;
protocol="application/pgp-signature";
boundary="AmgjsFQoK7WLdA11lA1Fk4k1nN3q2qrZU"

This is an OpenPGP/MIME signed message (RFC 4880 and 3156)
--AmgjsFQoK7WLdA11lA1Fk4k1nN3q2qrZU
Content-Type: multipart/mixed;
boundary="zU7ELd7FBao4WSYAg3sTaUmtBCDCDRg7h";
protected-headers="v1"
From: Marc Deslauriers <marc.deslauriers@canonical.com>
Reply-To: Ubuntu Security <security@ubuntu.com>
To: "ubuntu-security-announce@lists.ubuntu.com"
<ubuntu-security-announce@lists.ubuntu.com>
Message-ID: <b8b94a87-c0b1-8148-ad12-a09575635e69@canonical.com>
Subject: [USN-4897-1] Pygments vulnerability

--zU7ELd7FBao4WSYAg3sTaUmtBCDCDRg7h
Content-Type: text/plain; charset=utf-8
Content-Language: en-C
Content-Transfer-Encoding: quoted-printable

==========================================================================
Ubuntu Security Notice USN-4897-1
March 30, 2021

pygments vulnerability
==========================================================================

A security issue affects these releases of Ubuntu and its derivatives:

- Ubuntu 20.10
- Ubuntu 20.04 LTS
- Ubuntu 18.04 LTS
- Ubuntu 16.04 LTS

Summary:

Pygments could be made to hang if it opened a specially crafted file.

Software Description:
- pygments: Generic syntax highlighter

Details:

Ben Caller discovered that Pygments incorrectly handled parsing certain
files. If a user or automated system were tricked into parsing a specially
crafted file, a remote attacker could cause Pygments to hang or consume
resources, resulting in a denial of service.

Update instructions:

The problem can be corrected by updating your system to the following
package versions:

Ubuntu 20.10:
python3-pygments 2.3.1+dfsg-4ubuntu0.2

Ubuntu 20.04 LTS:
python-pygments 2.3.1+dfsg-1ubuntu2.2
python3-pygments 2.3.1+dfsg-1ubuntu2.2

Ubuntu 18.04 LTS:
python-pygments 2.2.0+dfsg-1ubuntu0.2
python3-pygments 2.2.0+dfsg-1ubuntu0.2

Ubuntu 16.04 LTS:
python-pygments 2.1+dfsg-1ubuntu0.2
python3-pygments 2.1+dfsg-1ubuntu0.2

In general, a standard system update will make all the necessary changes.

References:
https://ubuntu.com/security/notices/USN-4897-1
CVE-2021-27291

Package Information:
https://launchpad.net/ubuntu/+source/pygments/2.3.1+dfsg-4ubuntu0.2
https://launchpad.net/ubuntu/+source/pygments/2.3.1+dfsg-1ubuntu2.2
https://launchpad.net/ubuntu/+source/pygments/2.2.0+dfsg-1ubuntu0.2
https://launchpad.net/ubuntu/+source/pygments/2.1+dfsg-1ubuntu0.2


--zU7ELd7FBao4WSYAg3sTaUmtBCDCDRg7h--

--AmgjsFQoK7WLdA11lA1Fk4k1nN3q2qrZU
Content-Type: application/pgp-signature; name="OpenPGP_signature.asc"
Content-Description: OpenPGP digital signature
Content-Disposition: attachment; filename="OpenPGP_signature"

-----BEGIN PGP SIGNATURE-----

iQIzBAEBCgAdFiEEUMSg3c8x5FLOsZtRZWnYVadEvpMFAmBjYgUACgkQZWnYVadE
vpPEFRAAg7bo92nXdgLgXlBJm1nYhO00YUUcy4AWeeNkgzgIv0pVdm8V8IVLRb2A
J+P8Zhn1TtqDa5cOdMdFp+v/KqOClU35g8G5zdxMndzLkV7rKiSwfaAbN+PW7fjI
PEJS2WHQ9dR8WyWB1VBxDavmccfb/fio8RiRTmne0B1H9bRawgwMV9nlrQ/9ZC3X
JIC4nacjXxUgkzKaLmukchhQdUqS6oG4NMfZMBW6iF/MAgADp4JnlxXqPQB3+0BU
dywxdWlJ1B8wPXCbWx81YrfmPNPP+dBBh2VDesB99vZRGYjvBepqXSSa0BI35NJj
WIcynl2dhO33tiV+tBoQVdITb58PqnvXDPRNXuH2AHeIwTcfPkkQkPfekds5ZlbX
h1onbk1Z45uX+TQuXx9lyQLR4A7nXHV3JKdfkdYBs1A/xag4lpasLCJ7krzJ/qfC
ptVUDzcJP+aRCCaot7teg3hbtP42u6oanFYETWrlWR9fzyF35ADdXrvYgDfJ4zWm
dEZEJYineVFTYLet0mYjcMfYHSWI58v2fAmyisFUa4OQ9KOBBWuFGPMNuQ4JzSR+
6AJciaf9sKiBYaSLGVM6J6nqiJsP6V3utU5PABYDLjUBCrDBpsxSoAWzCFEjbg0A
rPFU4wZ8ItSSCE3u3RLLnAAmH8krj+6UzzWHilRfRb/baPp8VKA=
=jY5G
-----END PGP SIGNATURE-----

--AmgjsFQoK7WLdA11lA1Fk4k1nN3q2qrZU--


--===============0087223769808489116==
Content-Type: text/plain; charset="utf-8"
MIME-Version: 1.0
Content-Transfer-Encoding: base64
Content-Disposition: inline

LS0gCnVidW50dS1zZWN1cml0eS1hbm5vdW5jZSBtYWlsaW5nIGxpc3QKdWJ1bnR1LXNlY3VyaXR5
LWFubm91bmNlQGxpc3RzLnVidW50dS5jb20KTW9kaWZ5IHNldHRpbmdzIG9yIHVuc3Vic2NyaWJl
IGF0OiBodHRwczovL2xpc3RzLnVidW50dS5jb20vbWFpbG1hbi9saXN0aW5mby91YnVudHUtc2Vj
dXJpdHktYW5ub3VuY2UK

--===============0087223769808489116==--
Pro-Linux
Pro-Linux @Facebook
Neue Nachrichten
Werbung