QID 198315

Date Published: 2021-04-06

QID 198315: Ubuntu Security Notification for Pygments Vulnerability (USN-4897-1)

It was discovered that Pygments incorrectly handled parsing certain files.

If a user or automated system were tricked into parsing a specially crafted file, a remote attacker could cause Pygments to hang or consume resources, resulting in a denial of service.

  • CVSS V3 rated as High - 7.5 severity.
  • CVSS V2 rated as Medium - 5 severity.
  • Solution
    Refer to Ubuntu advisory USN-4897-1 for affected packages and patching details, or update with your package manager.
    Vendor References

    CVEs related to QID 198315

    Software Advisories
    Advisory ID Software Component Link
    USN-4897-1 16.04 (Xenial) on src python-pygments URL Logo launchpad.net/ubuntu/+source/pygments/2.1+dfsg-1ubuntu0.2
    USN-4897-1 16.04 (Xenial) on src python3-pygments URL Logo launchpad.net/ubuntu/+source/pygments/2.1+dfsg-1ubuntu0.2
    USN-4897-1 18.04 (bionic) on src python-pygments URL Logo launchpad.net/ubuntu/+source/pygments/2.2.0+dfsg-1ubuntu0.2
    USN-4897-1 18.04 (bionic) on src python3-pygments URL Logo launchpad.net/ubuntu/+source/pygments/2.2.0+dfsg-1ubuntu0.2
    USN-4897-1 20.04 (focal) on src python-pygments URL Logo launchpad.net/ubuntu/+source/pygments/2.3.1+dfsg-1ubuntu2.2
    USN-4897-1 20.04 (focal) on src python3-pygments URL Logo launchpad.net/ubuntu/+source/pygments/2.3.1+dfsg-1ubuntu2.2
    USN-4897-1 20.10 (groovy) on src python3-pygments URL Logo launchpad.net/ubuntu/+source/pygments/2.3.1+dfsg-4ubuntu0.2