-----BEGIN PGP SIGNED MESSAGE-----
Hash: SHA256

===========================================================================
             AUSCERT External Security Bulletin Redistribution

                               ESB-2021.1070
                         pygments security update
                               29 March 2021

===========================================================================

        AusCERT Security Bulletin Summary
        ---------------------------------

Product:           pygments
Publisher:         Debian
Operating System:  Debian GNU/Linux
Impact/Access:     Denial of Service -- Remote/Unauthenticated
Resolution:        Patch/Upgrade
CVE Names:         CVE-2021-27291  

Reference:         ESB-2021.0984

Original Bulletin: 
   http://www.debian.org/security/2021/dsa-4878

- --------------------------BEGIN INCLUDED TEXT--------------------

- -----BEGIN PGP SIGNED MESSAGE-----
Hash: SHA512

- - -------------------------------------------------------------------------
Debian Security Advisory DSA-4878-1                   security@debian.org
https://www.debian.org/security/                       Moritz Muehlenhoff
March 27, 2021                        https://www.debian.org/security/faq
- - -------------------------------------------------------------------------

Package        : pygments
CVE ID         : CVE-2021-27291
Debian Bug     : 985574

Ben Caller discovered that Pygments, a syntax highlighting package
written in Python 3, used regular expressions which could result in
denial of service.

For the stable distribution (buster), this problem has been fixed in
version 2.3.1+dfsg-1+deb10u2.

We recommend that you upgrade your pygments packages.

For the detailed security status of pygments please refer to
its security tracker page at:
https://security-tracker.debian.org/tracker/pygments

Further information about Debian Security Advisories, how to apply
these updates to your system and frequently asked questions can be
found at: https://www.debian.org/security/

Mailing list: debian-security-announce@lists.debian.org
- -----BEGIN PGP SIGNATURE-----

iQIzBAEBCgAdFiEEtuYvPRKsOElcDakFEMKTtsN8TjYFAmBfObwACgkQEMKTtsN8
TjaqqA/8C6+tyAxWYXb6n1R+nXZEbOXW26WqQQf88Z7obXKkfoiB3NMHSjioJT/r
/BfCxaZgrp09u2pmMJreA08Pgjmov/X4kMdhwWg5+hdtpP2DFRHVT4usW4/3z3h7
Y8iSVNa9RJPBfpOkn2o85exrvXH/csTJ/Mvt077yii8sT3pXWRWlH9+iczWGH5kX
C40vZ3JcNZU1mjpZI7jTxwONIjsuAeoC1xDoL2nHoOt1UrYeigx6VpzQxXQxEq5O
XD0o7CxN1aBZMMKD6e4xUNY9MXCJZt3kpGx39lKnbUSHgKBFhEEEznjdoD8hLgul
taa2+86+JxX8YCGGjzqIWopgYdW5LedJNflVXzS7TSgiITYU+LV+jTB5XIPufC4b
uCmUdThEt5xUWxsNjV+r2Y2UH4mQl6QYUDOl/0CB5i968M0C+6/N6WPIYzGWLDZH
VUclMHUKmwTr4Kaks21dcoFhFOlCWfiD8PB2KDt+ImpdHA+f1dL3pE0WdG8/wVfx
MXRZe6EwDNygujq/xid4K3sT4i9GyPFY4LhOb3bgytyVDHR4jxQxUQGwpXDf/1Mu
aJoEOjUWIMod6ur1GFmi7WjLG+cVU3ZrkQ0PRUQiCDTdmGVgYHlfIrvpRw2gG1G3
mZBrmOexnkmCjUR3Dg207O/cURqpyw7tbGa/IRcxwGgN9hSMJtg=
=AVWk
- -----END PGP SIGNATURE-----

- --------------------------END INCLUDED TEXT--------------------

You have received this e-mail bulletin as a result of your organisation's
registration with AusCERT. The mailing list you are subscribed to is
maintained within your organisation, so if you do not wish to continue
receiving these bulletins you should contact your local IT manager. If
you do not know who that is, please send an email to auscert@auscert.org.au
and we will forward your request to the appropriate person.

NOTE: Third Party Rights
This security bulletin is provided as a service to AusCERT's members.  As
AusCERT did not write the document quoted above, AusCERT has had no control
over its content. The decision to follow or act on information or advice
contained in this security bulletin is the responsibility of each user or
organisation, and should be considered in accordance with your organisation's
site policies and procedures. AusCERT takes no responsibility for consequences
which may arise from following or acting on information or advice contained in
this security bulletin.

NOTE: This is only the original release of the security bulletin.  It may
not be updated when updates to the original are made.  If downloading at
a later date, it is recommended that the bulletin is retrieved directly
from the author's website to ensure that the information is still current.

Contact information for the authors of the original document is included
in the Security Bulletin above.  If you have any questions or need further
information, please contact them directly.

Previous advisories and external security bulletins can be retrieved from:

        https://www.auscert.org.au/bulletins/

===========================================================================
Australian Computer Emergency Response Team
The University of Queensland
Brisbane
Qld 4072

Internet Email: auscert@auscert.org.au
Facsimile:      (07) 3365 7031
Telephone:      (07) 3365 4417 (International: +61 7 3365 4417)
                AusCERT personnel answer during Queensland business hours
                which are GMT+10:00 (AEST).
                On call after hours for member emergencies only.
===========================================================================
-----BEGIN PGP SIGNATURE-----
Comment: http://www.auscert.org.au/render.html?it=1967

iQIVAwUBYGEgIuNLKJtyKPYoAQjNIA/6Av01GapAFiIwoU08uKcJJmT51OC75oph
p1aA+rNC3aHeVG4EGEcTSHmO6FvoVm4u99Sq9Ql5xh9NGevAD1Xvj6AsqgMCVGAg
9epfmlRvfKUiBMQ63D055BGwvTsdR+HHDriQSQDIMXgwLPoh0gI2/xZsK0aMudRW
NgJ8zV5ZK9DpLAicZTVMJIutqlumgx4HykQ/r3kmOGPPxcc1ZcafUGjyWbggn6EY
TeFcIF8cMwRd8VsVNhGmfosLxkDYI1IJjdIoNkUDcy06vYiRTWXgmdxoTZWOgR/9
sInu3fDfl7kCTAXvWlng9jYmirDLD7LSp8iz/lYkeOArxtbvjIRTPi4dEZgOfGHY
6MWWtiwHZouUMQ4aHYKQTLmj4XmpVp7j+KSbS97eDWXLsZ/XtvAabG/H2UaYUnft
9QexLSbFC9UMc2T/O9h++1tGCHzPWpYTgUpS5BJpmhgwe/q7Uwu93Rpt++Y/VSGt
/Cu5WFLALRLoGe7KBuH0EQFhCxbI8pLfUSmzGCGWFa4zpqiAkglP8VXeel+8hwqp
QYzxMb7vDw/iXepKFJcCp6GJHeIHw7qH40AfNDSbyvTua1D8Nw0egw4+KpKFcy7n
BNYHLsvzgVFzxKAhivLnlOd+q1fqpNrVGGqrqkWBpTU6uI+sQsEV91MeLNGghrjw
9MzHgnA8MBY=
=ypRq
-----END PGP SIGNATURE-----