CVE-2021-20270
23.03.2021, 17:15
An infinite loop in SMLLexer in Pygments versions 1.5 to 2.7.3 may lead to denial of service when performing syntax highlighting of a Standard ML (SML) source file, as demonstrated by input that only contains the "exception" keyword.
| Vendor | Product | Version |
|---|---|---|
| pygments | pygments | 1.5 ≤ 𝑥 ≤ 2.7.3 |
| redhat | openshift_container_platform | 3.11 |
| redhat | openshift_container_platform | 4.0 |
| redhat | openstack_platform | 10.0 |
| redhat | software_collections | - |
| redhat | enterprise_linux | 7.0 |
| redhat | enterprise_linux | 8.0 |
| debian | debian_linux | 9.0 |
| debian | debian_linux | 10.0 |
𝑥
= Vulnerable software versions
Debian Releases
Debian Product | |||||||||||||
|---|---|---|---|---|---|---|---|---|---|---|---|---|---|
| mediawiki |
| ||||||||||||
| pygments |
|
Ubuntu Releases
Ubuntu Product | |||||||||||||||||||||
|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|
| pygments |
|
Common Weakness Enumeration
References