Narpat Mali
b402c3ac78
python3-pygments: Fix CVE-2022-40896
...
CVE-2022-40896:
A ReDoS issue was discovered in pygments/lexers/smithy.py in pygments
through 2.15.0 via SmithyLexer.
The CVE issue is fixed by 3 different commits between the releases 2.14.0
(for Smithy lexer), 2.15.0 (for SQL+Jinja lexers) and 2.15.1 (for Java
properties) as per: https://pyup.io/posts/pyup-discovers-redos-vulnerabilities-in-top-python-packages-part-2/
1. Smithy lexer commit from 2.14.0 release applies successfully on 2.11.2 version.
Commit: dd52102c38
Hence, backported the patch as CVE-2022-40896.patch.
2. SQL+Jinja lexers commit from 2.15.0 release doesn't apply on 2.11.2 version.
Commit: 97eb3d5ec7
Actually, this code doesn't exist in 2.11.2 version and it has been introduce by
python3-pygments 2.13.0 version. Hence, this is not vulnerable for 2.11.2 version.
SQL+Jinja lexers is introduced by: 0bdbd5992b
3. Java properties commit from 2.15.1 release also doesn't apply on 2.11.2 version.
Commit: fdf182a7af
Actually, this code also doesn't exist in 2.11.2 version as the code has been modified
in python3-pygments 2.14.0 by: a38cb38e93
Hence, this is also not vulnerable for 2.11.2 version.
(From OE-Core rev: ebb224e65a7e1402ccf0d9517bd72748c18e012e)
Signed-off-by: Narpat Mali <narpat.mali@windriver.com >
Signed-off-by: Steve Sakoman <steve@sakoman.com >
2023-09-18 04:28:03 -10:00
..
2021-12-17 09:56:14 +00:00
2023-08-02 04:47:13 -10:00
2020-11-30 14:42:22 +00:00
2022-03-16 08:48:08 +00:00
2023-08-19 05:56:58 -10:00
2023-05-10 04:19:56 -10:00
2021-08-22 22:21:47 +01:00
2022-03-16 08:48:09 +00:00
2020-09-21 23:54:39 +01:00
2021-11-26 17:01:08 +00:00
2022-11-20 08:19:17 +00:00
2020-09-21 23:54:39 +01:00
2020-11-30 14:42:22 +00:00
2022-02-08 14:20:18 +00:00
2020-04-26 14:00:51 +01:00
2022-02-25 15:07:50 +00:00
2020-11-30 14:42:22 +00:00
2022-03-16 08:48:08 +00:00
2022-03-18 23:27:27 +00:00
2023-09-18 04:28:03 -10:00
2022-03-16 08:48:08 +00:00
2023-06-14 04:16:59 -10:00
2021-08-12 06:26:16 +01:00
2023-01-26 23:37:05 +00:00
2022-02-25 15:07:50 +00:00
2022-02-25 15:07:50 +00:00
2020-11-30 14:42:22 +00:00
2021-11-26 17:01:08 +00:00
2023-01-26 23:37:05 +00:00
2021-11-26 17:01:08 +00:00
2023-09-08 16:09:41 -10:00
2022-03-18 23:27:27 +00:00
2022-03-30 13:07:41 +01:00
2021-08-02 15:44:10 +01:00
2022-03-20 00:02:22 +00:00
2022-03-18 23:27:27 +00:00
2022-03-20 00:02:22 +00:00
2023-08-19 05:56:58 -10:00
2022-03-16 08:48:08 +00:00
2022-03-18 23:27:28 +00:00
2023-05-10 04:19:56 -10:00
2022-03-18 23:32:46 +00:00
2022-03-09 11:46:27 +00:00
2022-01-12 21:09:01 +00:00
2022-03-30 13:07:41 +01:00
2022-03-17 16:44:33 +00:00
2022-02-18 11:37:12 +00:00
2022-03-17 16:44:33 +00:00
2023-08-30 04:46:36 -10:00
2021-11-03 11:12:25 +00:00
2022-03-30 13:07:41 +01:00
2021-12-17 09:56:15 +00:00
2022-03-30 13:07:41 +01:00
2022-03-20 00:02:22 +00:00
2022-03-20 00:02:22 +00:00
2022-02-20 16:45:25 +00:00
2022-03-17 16:44:33 +00:00
2022-03-16 08:48:08 +00:00
2022-04-03 10:40:31 +01:00
2021-11-26 17:01:08 +00:00
2022-03-20 00:02:22 +00:00
2022-03-12 09:20:03 +00:00
2022-03-12 09:20:03 +00:00
2022-11-20 08:19:17 +00:00
2022-03-20 00:02:22 +00:00
2022-03-23 12:13:50 +00:00
2022-03-12 09:20:03 +00:00
2022-03-18 23:27:27 +00:00
2022-03-16 10:31:41 +00:00
2022-03-20 00:02:22 +00:00
2022-02-16 09:46:29 +00:00
2022-02-16 09:46:29 +00:00
2022-08-28 07:51:30 +01:00
2022-03-20 00:02:22 +00:00
2022-03-16 08:48:08 +00:00
2022-03-16 08:48:08 +00:00
2022-03-16 08:48:08 +00:00
2022-03-16 08:48:08 +00:00
2022-03-20 00:02:22 +00:00
2022-03-18 23:27:27 +00:00
2022-03-10 13:07:37 +00:00
2022-03-16 08:48:08 +00:00
2022-02-10 10:32:08 +00:00
2022-02-10 10:32:08 +00:00
2022-02-10 10:32:08 +00:00
2023-09-18 04:28:03 -10:00
2022-02-20 16:45:25 +00:00
2022-03-18 23:27:27 +00:00
2022-03-16 13:39:12 +00:00
2022-03-20 00:02:22 +00:00
2022-03-18 23:27:27 +00:00
2023-02-15 21:46:55 +00:00
2022-03-30 13:07:41 +01:00
2022-03-30 13:07:41 +01:00
2022-03-30 13:07:41 +01:00
2022-03-20 00:02:22 +00:00
2023-06-14 04:16:59 -10:00
2021-11-29 23:07:13 +00:00
2022-09-28 08:02:11 +01:00
2022-02-20 16:45:25 +00:00
2022-02-16 09:46:29 +00:00
2022-03-10 13:07:37 +00:00
2022-03-20 00:02:22 +00:00
2023-01-26 23:37:05 +00:00
2023-03-20 17:20:44 +00:00
2022-03-20 00:02:22 +00:00
2021-05-16 08:29:59 +01:00
2022-02-25 15:07:50 +00:00
2021-10-18 13:48:17 +01:00
2022-03-18 23:27:27 +00:00
2021-05-21 15:18:23 +01:00
2022-03-18 23:27:28 +00:00
2022-03-23 12:13:50 +00:00
2022-03-18 23:27:28 +00:00
2022-03-18 23:27:27 +00:00
2022-03-18 23:27:28 +00:00
2022-03-18 23:27:28 +00:00
2022-03-18 23:27:27 +00:00
2022-03-18 23:27:28 +00:00
2022-03-12 09:20:03 +00:00
2022-03-12 09:20:03 +00:00
2021-07-24 16:33:47 +01:00
2021-08-02 15:44:10 +01:00
2022-03-17 16:44:33 +00:00
2022-03-20 00:02:22 +00:00
2021-08-02 15:44:10 +01:00
2022-03-30 13:07:41 +01:00
2021-11-26 17:01:08 +00:00
2021-08-02 15:44:10 +01:00
2021-11-26 17:01:08 +00:00
2023-01-26 23:37:05 +00:00
2022-03-20 00:02:22 +00:00
2021-08-02 15:44:10 +01:00
2022-03-09 11:46:27 +00:00
2020-06-23 12:31:03 +01:00
2021-11-03 11:12:25 +00:00
2021-08-02 15:44:10 +01:00
2022-03-18 23:27:27 +00:00
2022-02-03 09:05:14 +00:00
2021-08-02 15:44:10 +01:00
2021-08-02 15:44:10 +01:00