Overly broad permissions can turn one compromised account into a much larger security problem. Learn how to reduce unnecessary access, review privileges, and apply least privilege across modern Linux systems. Review Linux Privileges×

Alerts This Week
Warning Icon 1 515
Alerts This Week
Warning Icon 1 515

Ubuntu 15.10: USN-2862-1 Moderate: Pygments Code Execution Risk

ubuntu
Calendar Grey January 7, 2016
Scroller Ubuntu
Vulnerabilities in Pygments might be leveraged to trigger failures or permit the running of harmful scripts through specially designed font queries.
Pygments could be made to crash or run programs if it processed a specially crafted font request.

Summary

Pygments could be made to crash or run programs if it processed a specially

crafted font request.

Software Description:

- pygments: syntax highlighting package written in Python

Details:

It was discovered that Pygments incorrectly sanitized strings used to

search system fonts. An attacker could possibly use this issue to execute

arbitrary code.

Update Instructions

The problem can be corrected by updating your system to the following
package versions:

Ubuntu 15.10:
  python-pygments                 2.0.1+dfsg-1.1svn1.1
  python3-pygments                2.0.1+dfsg-1.1svn1.1

Ubuntu 15.04:
  python-pygments                 2.0.1+dfsg-1svn1.1
  python3-pygments                2.0.1+dfsg-1svn1.1

Ubuntu 14.04 LTS:
  python-pygments                 1.6+dfsg-1ubuntu1.1
  python3-pygments                1.6+dfsg-1ubuntu1.1

Ubuntu 12.04 LTS:
  python-pygments                 1.4+dfsg-2ubuntu0.1
  python3-pygments                1.4+dfsg-2ubuntu0.1

In general, a standard system update will make all the necessary changes.

References

https://ubuntu.com/security/notices/USN-2862-1

CVE-2015-8557

January 07, 2016

Package Information

Get the latest News and Insights

Get the latest Linux and open source security news straight to your inbox.