-----BEGIN PGP SIGNED MESSAGE----- Hash: SHA256 - ------------------------------------------------------------------------- Debian LTS Advisory DLA-2600-1 [email protected] https://www.debian.org/lts/security/ Chris Lamb March 19, 2021 https://wiki.debian.org/LTS - -------------------------------------------------------------------------
Package : pygments Version : 2.2.0+dfsg-1+deb9u2 CVE ID : CVE-2021-27291 It was discovered that there was a series of denial of service vulnerabilities in Pygments, a popular syntax highlighting library for Python. A number of regular expressions had exponential or cubic worst-case complexity which could cause a remote denial of service (DoS) when provided with malicious input. For Debian 9 "Stretch", this problem has been fixed in version 2.2.0+dfsg-1+deb9u2. We recommend that you upgrade your pygments packages. For the detailed security status of pygments please refer to its security tracker page at: https://security-tracker.debian.org/tracker/pygments Further information about Debian LTS security advisories, how to apply these updates to your system and frequently asked questions can be found at: https://wiki.debian.org/LTS -----BEGIN PGP SIGNATURE----- iQIzBAEBCAAdFiEEwv5L0nHBObhsUz5GHpU+J9QxHlgFAmBU3YYACgkQHpU+J9Qx HlhRlg//dgpChnkOi8GP8eesoKF4txCJ8SpqVHRXbke13cPUMLBpdAah7YrcEyhe Zm8lJWdLLDPznTRLvm50jr546Spj5aVdj4U+AeYkYYkQZJvQu3l4kt3Mz0vUVqIk NW3P6aMVadybQby5NVBPQyWkfj4ZiRwGl5YgqpNMHiIpcKMJvu1t27CV/J+KcNmw aWEM7ddXQFLbSsCI4gH6orOkrSqijpRFyak1yDRD6m5mU9BLFG1sWA/vK0vPNkB1 KKRZrs5ucmmxWdarrTdCHraS+tKMlBYApaGHBgCPqW5sKSA2GZycCzXv5KBw+6KP uocFmCAhns4R4rdE9Gh3oNU72YpFivE2Rls6YUwK65TQu9OHVZMdHqYrPsXtBJQJ mRdLvSUfBQ/AFKytLEo9FZ0VtPrybNoVLB+bcP7GHuEiwOD6H40g82MYGxjYSXu7 z94ctcWix9lEtpsyCgN0TfzfZgAk711z6bZM6jJssKVpokacrWNOqOlc88hM1vFK sUBWqOuM2zkaKb1ai6ovfZK8titRFrEyizOXl/hhCR7HUGJFJswV7fq2+OWlUDeZ Utrpx9tF14g68DWYzbtzzSVQm88ZD80BA3ChORfMXC0BQM4GtZMODf5whOzM6kVc 6WsFHKnBQ1FESEFcdOQHHVZmyw2IF94kfP777vAGvuvTZqSp0eM= =xveQ -----END PGP SIGNATURE-----
