emacs-bug-tracker
[Top][All Lists]
Advanced

[Date Prev][Date Next][Thread Prev][Thread Next][Date Index][Thread Index]

bug#47351: closed (python-pygments@2.7.3 is vulnerable to at least CVE-2


From: GNU bug Tracking System
Subject: bug#47351: closed (python-pygments@2.7.3 is vulnerable to at least CVE-2021-20270)
Date: Wed, 23 Mar 2022 02:33:02 +0000

Your message dated Tue, 22 Mar 2022 22:31:58 -0400
with message-id <878rt11js1.fsf@gmail.com>
and subject line Re: bug#47351: python-pygments@2.7.3 is vulnerable to at least 
CVE-2021-20270
has caused the debbugs.gnu.org bug report #47351,
regarding python-pygments@2.7.3 is vulnerable to at least CVE-2021-20270
to be marked as done.

(If you believe you have received this mail in error, please contact
help-debbugs@gnu.org.)


-- 
47351: http://debbugs.gnu.org/cgi/bugreport.cgi?bug=47351
GNU Bug Tracking System
Contact help-debbugs@gnu.org with problems
--- Begin Message --- Subject: python-pygments@2.7.3 is vulnerable to at least CVE-2021-20270 Date: Wed, 24 Mar 2021 00:20:14 +0100 User-agent: Evolution 3.34.2
CVE-2021-20270  23.03.21 18:15
An infinite loop in SMLLexer in Pygments
versions 1.5 to 2.7.3 may lead to denial of service when performing
syntax highlighting of a Standard ML (SML) source file, as demonstrated
by input that only contains the "exception" keyword.

Upstream version 2.8.1 is not affected.

Because this package would cause 456 dependents to be rebuilt, I
prepared 69e3b7f4bea9ab6c9520c5b5bdc14e0388475c3d and will push soon to
staging once master is merged in it so that .guix-authorizations
contains my key. I also attached the patch (trivial).

Opening this bug to track when this lands into master

Attachment: 0001-gnu-python-pygments-Update-to-2.8.1-security-fixes.patch
Description: Text Data

Attachment: signature.asc
Description: This is a digitally signed message part


--- End Message ---
--- Begin Message --- Subject: Re: bug#47351: python-pygments@2.7.3 is vulnerable to at least CVE-2021-20270 Date: Tue, 22 Mar 2022 22:31:58 -0400 User-agent: Gnus/5.13 (Gnus v5.13) Emacs/27.2 (gnu/linux)
Léo Le Bouter <lle-bout@zaclys.net> writes:

> CVE-2021-20270        23.03.21 18:15
> An infinite loop in SMLLexer in Pygments
> versions 1.5 to 2.7.3 may lead to denial of service when performing
> syntax highlighting of a Standard ML (SML) source file, as demonstrated
> by input that only contains the "exception" keyword.
>
> Upstream version 2.8.1 is not affected.

Which is now the current version packaged in Guix.

Thanks for the report!

Closing.

Maxim


--- End Message ---

reply via email to

[Prev in Thread] Current Thread [Next in Thread]