Pygments could be made to crash if it received specially crafted input.. ========================================================================== Ubuntu Security Notice USN-7128-1 November 26, 2024 pygments vulnerability ========================================================================== A security issue affects these releases of Ubuntu and its derivatives: - Ubuntu 22.04 LTS Summary: Pygments could be made to crash if it received specially crafted input. Software Description: - pygments: Generic syntax highlighter Details: Sebastian Chnelik discovered that Pygments had an inefficient regex query for analyzing certain inputs. An attacker could possibly use this issue to cause a denial of service. Update instructions: The problem can be corrected by updating your system to the following package versions: Ubuntu 22.04 LTS python3-pygments 2.11.2+dfsg-2ubuntu0.1 In general, a standard system update will make all the necessary changes. References: https://ubuntu.com/security/notices/USN-7128-1 CVE-2022-40896 Package Information: https://launchpad.net/ubuntu/+source/pygments/2.11.2+dfsg-2ubuntu0.1 . A critical flaw in Pygments impacts Ubuntu 22.04 LTS, leading to unexpected terminations when handling maliciously designed inputs.. Pygments Security, Ubuntu Advisory, Denial Of Service, Python Package Issue. . Severity: Important. LinuxSecurity.com Team
Pygments could be made to hang if it opened a specially crafted file.. ========================================================================== Ubuntu Security Notice USN-4897-2 August 14, 2023 pygments vulnerabilities ========================================================================== A security issue affects these releases of Ubuntu and its derivatives: - Ubuntu 14.04 LTS (Available with Ubuntu Pro) Summary: Pygments could be made to hang if it opened a specially crafted file. Software Description: - pygments: Generic syntax highlighter Details: USN-4897-1 fixed several vulnerabilities in Pygments. This update provides the corresponding update for Ubuntu 14.04 LTS. Original advisory details: Ben Caller discovered that Pygments incorrectly handled parsing certain files. If a user or automated system were tricked into parsing a specially crafted file, a remote attacker could cause Pygments to hang or consume resources, resulting in a denial of service. (CVE-2021-27291) It was discovered that Pygments incorrectly handled parsing certain files. An attacker could possibly use this issue to cause a denial of service. (CVE-2021-20270) Update instructions: The problem can be corrected by updating your system to the following package versions: Ubuntu 14.04 LTS (Available with Ubuntu Pro): python-pygments 1.6+dfsg-1ubuntu1.1+esm1 python3-pygments 1.6+dfsg-1ubuntu1.1+esm1 In general, a standard system update will make all the necessary changes. References: https://ubuntu.com/security/notices/USN-4897-2 https://ubuntu.com/security/notices/USN-4897-1 CVE-2021-20270, CVE-2021-27291 . Ubuntu 14.04 has received security advisories addressing vulnerabilities in Pygments due to inadequate file handling, potentially permitting Denial of Service (DoS) attacks. Ubuntu Pygments Update, Denial of Service Risks, Security Notices. . Severity: Critical. LinuxSecurity.com Team
Pygments could be made to hang if it opened a specially crafted file.. =========================================================================Ubuntu Security Notice USN-4897-1 March 30, 2021 pygments vulnerability ========================================================================= A security issue affects these releases of Ubuntu and its derivatives: - Ubuntu 20.10 - Ubuntu 20.04 LTS - Ubuntu 18.04 LTS - Ubuntu 16.04 LTS Summary: Pygments could be made to hang if it opened a specially crafted file. Software Description: - pygments: Generic syntax highlighter Details: Ben Caller discovered that Pygments incorrectly handled parsing certain files. If a user or automated system were tricked into parsing a specially crafted file, a remote attacker could cause Pygments to hang or consume resources, resulting in a denial of service. Update instructions: The problem can be corrected by updating your system to the following package versions: Ubuntu 20.10: python3-pygments 2.3.1+dfsg-4ubuntu0.2 Ubuntu 20.04 LTS: python-pygments 2.3.1+dfsg-1ubuntu2.2 python3-pygments 2.3.1+dfsg-1ubuntu2.2 Ubuntu 18.04 LTS: python-pygments 2.2.0+dfsg-1ubuntu0.2 python3-pygments 2.2.0+dfsg-1ubuntu0.2 Ubuntu 16.04 LTS: python-pygments 2.1+dfsg-1ubuntu0.2 python3-pygments 2.1+dfsg-1ubuntu0.2 In general, a standard system update will make all the necessary changes. References: https://ubuntu.com/security/notices/USN-4897-1 CVE-2021-27291 Package Information: https://launchpad.net/ubuntu/+source/pygments/2.3.1+dfsg-4ubuntu0.2 https://launchpad.net/ubuntu/+source/pygments/2.3.1+dfsg-1ubuntu2.2 https://launchpad.net/ubuntu/+source/pygments/2.2.0+dfsg-1ubuntu0.2 https://launchpad.net/ubuntu/+source/pygments/2.1+dfsg-1ubuntu0.2 . The security bulletin USN-4897-1 from Ubuntu points out a flaw in Pygments that may result in possibledenial of service vulnerabilities.. Pygments vulnerability, Ubuntu update, denial of service. . Severity: Critical. LinuxSecurity.com Team
Ben Caller discovered that Pygments, a syntax highlighting package written in Python 3, used regular expressions which could result in denial of service. . -----BEGIN PGP SIGNED MESSAGE----- Hash: SHA512 - ------------------------------------------------------------------------- Debian Security Advisory DSA-4878-1
It was discovered that Pygments, a syntax highlighting package written in Python, could be forced into an infinite loop, resulting in denial of service. . -----BEGIN PGP SIGNED MESSAGE----- Hash: SHA512 - ------------------------------------------------------------------------- Debian Security Advisory DSA-4870-1
Javantea discovered that pygments, a generic syntax highlighter, is prone to a shell injection vulnerability allowing a remote attacker to execute arbitrary code via shell metacharacters in a font name. . - ------------------------------------------------------------------------- Debian Security Advisory DSA-3445-1
Pygments could be made to crash or run programs if it processed a specially crafted font request.. =========================================================================Ubuntu Security Notice USN-2862-1 January 07, 2016 pygments vulnerability ========================================================================= A security issue affects these releases of Ubuntu and its derivatives: - Ubuntu 15.10 - Ubuntu 15.04 - Ubuntu 14.04 LTS - Ubuntu 12.04 LTS Summary: Pygments could be made to crash or run programs if it processed a specially crafted font request. Software Description: - pygments: syntax highlighting package written in Python Details: It was discovered that Pygments incorrectly sanitized strings used to search system fonts. An attacker could possibly use this issue to execute arbitrary code. Update instructions: The problem can be corrected by updating your system to the following package versions: Ubuntu 15.10: python-pygments 2.0.1+dfsg-1.1svn1.1 python3-pygments 2.0.1+dfsg-1.1svn1.1 Ubuntu 15.04: python-pygments 2.0.1+dfsg-1svn1.1 python3-pygments 2.0.1+dfsg-1svn1.1 Ubuntu 14.04 LTS: python-pygments 1.6+dfsg-1ubuntu1.1 python3-pygments 1.6+dfsg-1ubuntu1.1 Ubuntu 12.04 LTS: python-pygments 1.4+dfsg-2ubuntu0.1 python3-pygments 1.4+dfsg-2ubuntu0.1 In general, a standard system update will make all the necessary changes. References: https://ubuntu.com/security/notices/USN-2862-1 CVE-2015-8557 Package Information: https://launchpad.net/ubuntu/+source/pygments/2.0.1+dfsg-1.1svn1.1 https://launchpad.net/ubuntu/+source/pygments/2.0.1+dfsg-1svn1.1 https://launchpad.net/ubuntu/+source/pygments/1.6+dfsg-1ubuntu1.1 https://launchpad.net/ubuntu/+source/pygments/1.4+dfsg-2ubuntu0.1 . Vulnerabilities in Pygments might be leveraged to trigger failures or permit the running of harmfulscripts through specially designed font queries.. Python Pygments, Security Notice, Program Crash, Font Request. . LinuxSecurity.com Team
Get the latest Linux and open source security news straight to your inbox.