VYPR

rpm package

suse/python-Pygments&distro=SUSE Linux Enterprise Server 15 SP1-BCL

pkg:rpm/suse/python-Pygments&distro=SUSE%20Linux%20Enterprise%20Server%2015%20SP1-BCL

Vulnerabilities (4)

  • CVE-2021-20270Mar 23, 2021
    affected < 2.6.1-7.7.1fixed 2.6.1-7.7.1

    An infinite loop in SMLLexer in Pygments versions 1.5 to 2.7.3 may lead to denial of service when performing syntax highlighting of a Standard ML (SML) source file, as demonstrated by input that only contains the "exception" keyword.

  • CVE-2021-27291Mar 17, 2021
    affected < 2.6.1-7.10.1fixed 2.6.1-7.10.1

    In pygments 1.1+, fixed in 2.7.4, the lexers used to parse programming languages rely heavily on regular expressions. Some of the regular expressions have exponential or cubic worst-case complexity and are vulnerable to ReDoS. By crafting malicious input, an attacker can cause a

  • CVE-2020-14343Feb 9, 2021
    affected < 2.6.1-7.4.1fixed 2.6.1-7.4.1

    A vulnerability was discovered in the PyYAML library in versions before 5.4, where it is susceptible to arbitrary code execution when it processes untrusted YAML files through the full_load method or with the FullLoader loader. Applications that use the library to process untrust

  • CVE-2020-25659Jan 11, 2021
    affected < 2.6.1-7.4.1fixed 2.6.1-7.4.1

    python-cryptography 3.2 is vulnerable to Bleichenbacher timing attacks in the RSA decryption API, via timed processing of valid PKCS#1 v1.5 ciphertext.