Bugzilla – Full Text Bug Listing |
Summary: | VUL-0: CVE-2021-27291: python-Pygments: ReDos via crafted malicious input | ||
---|---|---|---|
Product: | [Novell Products] SUSE Security Incidents | Reporter: | Robert Frohl <rfrohl> |
Component: | Incidents | Assignee: | Security Team bot <security-team> |
Status: | RESOLVED FIXED | QA Contact: | Security Team bot <security-team> |
Severity: | Normal | ||
Priority: | P3 - Medium | CC: | andreas.taschner, benoit.monin, gabriele.sonnu, meissner, smash_bz |
Version: | unspecified | ||
Target Milestone: | --- | ||
Hardware: | Other | ||
OS: | Other | ||
URL: | https://smash.suse.de/issue/279986/ | ||
Whiteboard: | CVSSv3.1:SUSE:CVE-2021-27291:7.5:(AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H) | ||
Found By: | Security Response Team | Services Priority: | |
Business Priority: | Blocker: | --- | |
Marketing QA Status: | --- | IT Deployment: | --- |
Description
Robert Frohl
2021-04-15 13:37:49 UTC
@Alberto: I saw that you took the last change. Maybe you would be interested to do this one too? tracking affected: - SUSE:SLE-12-SP1:Update/python-Pygments - SUSE:SLE-15:Update/python-Pygments - SUSE:SLE-15-SP1:Update/python-Pygments - SUSE:SLE-15-SP3:Update/python-Pygments fixed in openSUSE:Factory can you please submit fixes? (In reply to Marcus Meissner from comment #3) > can you please submit fixes? Sorry, I was not aware that I was assigned to this one. Working on it. Should be done: > - SUSE:SLE-12-SP1:Update/python-Pygments SR#259002 > - SUSE:SLE-15:Update/python-Pygments SR#259003 > - SUSE:SLE-15-SP1:Update/python-Pygments SR#259004 > - SUSE:SLE-15-SP3:Update/python-Pygments SR#259006 Anything missing? SUSE-SU-2021:3840-1: An update that fixes one vulnerability is now available. Category: security (important) Bug References: 1184812 CVE References: CVE-2021-27291 JIRA References: Sources used: SUSE Linux Enterprise Server for SAP 15-SP1 (src): python-Pygments-2.6.1-7.10.1 SUSE Linux Enterprise Server 15-SP1-LTSS (src): python-Pygments-2.6.1-7.10.1 SUSE Linux Enterprise Server 15-SP1-BCL (src): python-Pygments-2.6.1-7.10.1 SUSE Linux Enterprise Module for Basesystem 15-SP2 (src): python-Pygments-2.6.1-7.10.1 SUSE Linux Enterprise High Performance Computing 15-SP1-LTSS (src): python-Pygments-2.6.1-7.10.1 SUSE Linux Enterprise High Performance Computing 15-SP1-ESPOS (src): python-Pygments-2.6.1-7.10.1 SUSE Enterprise Storage 6 (src): python-Pygments-2.6.1-7.10.1 SUSE CaaS Platform 4.0 (src): python-Pygments-2.6.1-7.10.1 NOTE: This line indicates an update has been released for the listed product(s). At times this might be only a partial fix. If you have questions please reach out to maintenance coordination. openSUSE-SU-2021:3839-1: An update that fixes one vulnerability is now available. Category: security (important) Bug References: 1184812 CVE References: CVE-2021-27291 JIRA References: Sources used: openSUSE Leap 15.3 (src): python-Pygments-2.6.1-4.3.1 openSUSE-SU-2021:3841-1: An update that fixes one vulnerability is now available. Category: security (important) Bug References: 1184812 CVE References: CVE-2021-27291 JIRA References: Sources used: openSUSE Leap 15.3 (src): python-Pygments-2.2.0-4.9.1 SUSE-SU-2021:3841-1: An update that fixes one vulnerability is now available. Category: security (important) Bug References: 1184812 CVE References: CVE-2021-27291 JIRA References: Sources used: SUSE Linux Enterprise Server for SAP 15 (src): python-Pygments-2.2.0-4.9.1 SUSE Linux Enterprise Server 15-LTSS (src): python-Pygments-2.2.0-4.9.1 SUSE Linux Enterprise Module for Packagehub Subpackages 15-SP3 (src): python-Pygments-2.2.0-4.9.1 SUSE Linux Enterprise Module for Packagehub Subpackages 15-SP2 (src): python-Pygments-2.2.0-4.9.1 SUSE Linux Enterprise High Performance Computing 15-LTSS (src): python-Pygments-2.2.0-4.9.1 SUSE Linux Enterprise High Performance Computing 15-ESPOS (src): python-Pygments-2.2.0-4.9.1 NOTE: This line indicates an update has been released for the listed product(s). At times this might be only a partial fix. If you have questions please reach out to maintenance coordination. SUSE-SU-2021:3839-1: An update that fixes one vulnerability is now available. Category: security (important) Bug References: 1184812 CVE References: CVE-2021-27291 JIRA References: Sources used: SUSE Linux Enterprise Module for Basesystem 15-SP3 (src): python-Pygments-2.6.1-4.3.1 NOTE: This line indicates an update has been released for the listed product(s). At times this might be only a partial fix. If you have questions please reach out to maintenance coordination. openSUSE-SU-2021:1521-1: An update that fixes one vulnerability is now available. Category: security (important) Bug References: 1184812 CVE References: CVE-2021-27291 JIRA References: Sources used: openSUSE Leap 15.2 (src): python-Pygments-2.6.1-lp152.5.12.1 Done. |