Описание
Infinite Loop in Pygments
An infinite loop in SMLLexer in Pygments versions 1.5 to 2.7.3 may lead to denial of service when performing syntax highlighting of a Standard ML (SML) source file, as demonstrated by input that only contains the "exception" keyword.
Ссылки
- https://nvd.nist.gov/vuln/detail/CVE-2021-20270
- https://github.com/pygments/pygments/commit/f91804ff4772e3ab41f46e28d370f57898700333
- https://bugzilla.redhat.com/show_bug.cgi?id=1922136
- https://github.com/pypa/advisory-database/tree/main/vulns/pygments/PYSEC-2021-140.yaml
- https://lists.debian.org/debian-lts-announce/2021/05/msg00003.html
- https://lists.debian.org/debian-lts-announce/2021/05/msg00006.html
- https://www.debian.org/security/2021/dsa-4889
- https://www.oracle.com/security-alerts/cpuoct2021.html
Пакеты
Pygments
>= 1.5, < 2.7.4
2.7.4
Связанные уязвимости
An infinite loop in SMLLexer in Pygments versions 1.5 to 2.7.3 may lead to denial of service when performing syntax highlighting of a Standard ML (SML) source file, as demonstrated by input that only contains the "exception" keyword.
An infinite loop in SMLLexer in Pygments versions 1.5 to 2.7.3 may lead to denial of service when performing syntax highlighting of a Standard ML (SML) source file, as demonstrated by input that only contains the "exception" keyword.
An infinite loop in SMLLexer in Pygments versions 1.5 to 2.7.3 may lead to denial of service when performing syntax highlighting of a Standard ML (SML) source file, as demonstrated by input that only contains the "exception" keyword.
An infinite loop in SMLLexer in Pygments versions 1.5 to 2.7.3 may lea ...