First published: Mon Mar 22 2021(Updated: )
It was discovered that Pygments incorrectly handled parsing SML files. If a user or automated system were tricked into parsing a specially crafted SML file, a remote attacker could cause Pygments to hang, resulting in a denial of service.
Affected Software | Affected Version | How to fix |
---|---|---|
All of | ||
ubuntu/python3-pygments | <2.3.1+dfsg-4ubuntu0.1 | 2.3.1+dfsg-4ubuntu0.1 |
Ubuntu Ubuntu | =20.10 | |
All of | ||
ubuntu/python-pygments | <2.3.1+dfsg-1ubuntu2.1 | 2.3.1+dfsg-1ubuntu2.1 |
Ubuntu Ubuntu | =20.04 | |
All of | ||
ubuntu/python3-pygments | <2.3.1+dfsg-1ubuntu2.1 | 2.3.1+dfsg-1ubuntu2.1 |
Ubuntu Ubuntu | =20.04 | |
All of | ||
ubuntu/python-pygments | <2.2.0+dfsg-1ubuntu0.1 | 2.2.0+dfsg-1ubuntu0.1 |
Ubuntu Ubuntu | =18.04 | |
All of | ||
ubuntu/python3-pygments | <2.2.0+dfsg-1ubuntu0.1 | 2.2.0+dfsg-1ubuntu0.1 |
Ubuntu Ubuntu | =18.04 | |
All of | ||
ubuntu/python-pygments | <2.1+dfsg-1ubuntu0.1 | 2.1+dfsg-1ubuntu0.1 |
Ubuntu Ubuntu | =16.04 | |
All of | ||
ubuntu/python3-pygments | <2.1+dfsg-1ubuntu0.1 | 2.1+dfsg-1ubuntu0.1 |
Ubuntu Ubuntu | =16.04 |
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
The vulnerability ID for this Pygments vulnerability is USN-4885-1.
Pygments incorrectly handles parsing SML files.
If a user or automated system parses a specially crafted SML file, a remote attacker could cause Pygments to hang, resulting in a denial of service.
The following versions of Python-Pygments and Python3-Pygments are affected: 2.3.1+dfsg-4ubuntu0.1, 2.3.1+dfsg-1ubuntu2.1, 2.2.0+dfsg-1ubuntu0.1, 2.1+dfsg-1ubuntu0.1.
To fix this Pygments vulnerability, update Python-Pygments and Python3-Pygments to the specified remedy versions provided by Ubuntu.