[ALAS2-2023-2198] Amazon Linux 2 2017.12 - ALAS2-2023-2198: medium priority package update for python-pygments

Severity Medium
Affected Packages 1
CVEs 1

Package updates are available for Amazon Linux 2 that fix the following vulnerabilities:
In pygments 1.1+, fixed in 2.7.4, the lexers used to parse programming languages rely heavily on regular expressions. Some of the regular expressions have exponential or cubic worst-case complexity and are vulnerable to ReDoS. By crafting malicious input, an attacker can cause a denial of service.

Type Package URL Namespace Name / Product Version Distribution / Platform Arch Patch / Fix
Affected pkg:rpm/amazonlinux/python-pygments?arch=noarch&distro=amazonlinux-2 amazonlinux python-pygments < 1.4-10.amzn2.0.1 amazonlinux-2 noarch
# CVE Description CVSS EPSS EPSS Trend (30 days) Affected Products Weaknesses Security Advisories Exploits PoC Pubblication Date Modification Date
# CVE Description CVSS EPSS EPSS Trend (30 days) Affected Products Weaknesses Security Advisories PoC Pubblication Date Modification Date