Amazon Linux 2 Security Advisory: ALAS-2023-2198
Advisory Release Date: 2023-08-03 18:10 Pacific
Advisory Updated Date: 2023-08-08 22:02 Pacific
In pygments 1.1+, fixed in 2.7.4, the lexers used to parse programming languages rely heavily on regular expressions. Some of the regular expressions have exponential or cubic worst-case complexity and are vulnerable to ReDoS. By crafting malicious input, an attacker can cause a denial of service. (CVE-2021-27291)
Affected Packages:
python-pygments
Note:
This advisory is applicable to Amazon Linux 2 (AL2) Core repository. Visit this FAQ section for the difference between AL2 Core and AL2 Extras advisories.
Issue Correction:
Run yum update python-pygments to update your system.
noarch:
python-pygments-1.4-10.amzn2.0.1.noarch
src:
python-pygments-1.4-10.amzn2.0.1.src