ALAS2-2023-2117

Related Vulnerabilities: CVE-2021-27291  

In pygments 1.1+, fixed in 2.7.4, the lexers used to parse programming languages rely heavily on regular expressions. Some of the regular expressions have exponential or cubic worst-case complexity and are vulnerable to ReDoS. By crafting malicious input, an attacker can cause a denial of service. (CVE-2021-27291)

ALAS2-2023-2117


Amazon Linux 2 Security Advisory: ALAS-2023-2117
Advisory Release Date: 2023-07-05 22:01 Pacific
Advisory Updated Date: 2023-07-19 22:27 Pacific
Severity: Medium

Issue Overview:

In pygments 1.1+, fixed in 2.7.4, the lexers used to parse programming languages rely heavily on regular expressions. Some of the regular expressions have exponential or cubic worst-case complexity and are vulnerable to ReDoS. By crafting malicious input, an attacker can cause a denial of service. (CVE-2021-27291)


Affected Packages:

python3-pygments


Issue Correction:
Run yum update python3-pygments to update your system.

New Packages:
noarch:
    python3-pygments-2.2.0-3.amzn2.0.3.noarch
    python3-pygments-doc-2.2.0-3.amzn2.0.3.noarch

src:
    python3-pygments-2.2.0-3.amzn2.0.3.src