Blame SOURCES/bz1943464-python-pygments-fix-CVE-2021-27291.patch

27b8ba
From 2e7e8c4a7b318f4032493773732754e418279a14 Mon Sep 17 00:00:00 2001
27b8ba
From: Georg Brandl <georg@python.org>
27b8ba
Date: Mon, 11 Jan 2021 09:46:34 +0100
27b8ba
Subject: [PATCH] Fix several exponential/cubic complexity regexes found by Ben
27b8ba
 Caller/Doyensec
27b8ba
27b8ba
---
27b8ba
 pygments/lexers/archetype.py | 2 +-
27b8ba
 pygments/lexers/factor.py    | 4 ++--
27b8ba
 pygments/lexers/jvm.py       | 1 -
27b8ba
 pygments/lexers/matlab.py    | 6 +++---
27b8ba
 pygments/lexers/objective.py | 4 ++--
27b8ba
 pygments/lexers/templates.py | 2 +-
27b8ba
 pygments/lexers/varnish.py   | 2 +-
27b8ba
 8 files changed, 14 insertions(+), 12 deletions(-)
27b8ba
27b8ba
diff --git a/pygments/lexers/archetype.py b/pygments/lexers/archetype.py
27b8ba
index 65046613d..26f5ea8c9 100644
27b8ba
--- a/pygments/lexers/archetype.py
27b8ba
+++ b/pygments/lexers/archetype.py
27b8ba
@@ -58,7 +58,7 @@ class AtomsLexer(RegexLexer):
27b8ba
             (r'P((\d*(\.\d+)?[YyMmWwDd]){1,3}(T(\d*(\.\d+)?[HhMmSs]){,3})?|'
27b8ba
              r'T(\d*(\.\d+)?[HhMmSs]){,3})', Literal.Date),
27b8ba
             (r'[+-]?(\d+\.\d*|\.\d+|\d+)[eE][+-]?\d+', Number.Float),
27b8ba
-            (r'[+-]?(\d+)*\.\d+%?', Number.Float),
27b8ba
+            (r'[+-]?\d*\.\d+%?', Number.Float),
27b8ba
             (r'0x[0-9a-fA-F]+', Number.Hex),
27b8ba
             (r'[+-]?\d+%?', Number.Integer),
27b8ba
         ],
27b8ba
diff --git a/pygments/lexers/factor.py b/pygments/lexers/factor.py
27b8ba
index be7b30dff..9200547f9 100644
27b8ba
--- a/pygments/lexers/factor.py
27b8ba
+++ b/pygments/lexers/factor.py
27b8ba
@@ -265,7 +265,7 @@ class FactorLexer(RegexLexer):
27b8ba
             (r'(?:<PRIVATE|PRIVATE>)\s', Keyword.Namespace),
27b8ba
 
27b8ba
             # strings
27b8ba
-            (r'"""\s+(?:.|\n)*?\s+"""', String),
27b8ba
+            (r'"""\s(?:.|\n)*?\s"""', String),
27b8ba
             (r'"(?:\\\\|\\"|[^"])*"', String),
27b8ba
             (r'\S+"\s+(?:\\\\|\\"|[^"])*"', String),
27b8ba
             (r'CHAR:\s+(?:\\[\\abfnrstv]|[^\\]\S*)\s', String.Char),
27b8ba
@@ -322,7 +322,7 @@ class FactorLexer(RegexLexer):
27b8ba
         'slots': [
27b8ba
             (r'\s+', Text),
27b8ba
             (r';\s', Keyword, '#pop'),
27b8ba
-            (r'(\{\s+)(\S+)(\s+[^}]+\s+\}\s)',
27b8ba
+            (r'(\{\s+)(\S+)(\s[^}]+\s\}\s)',
27b8ba
              bygroups(Text, Name.Variable, Text)),
27b8ba
             (r'\S+', Name.Variable),
27b8ba
         ],
27b8ba
diff --git a/pygments/lexers/jvm.py b/pygments/lexers/jvm.py
27b8ba
index 62dfd45e5..9a9397c2d 100644
27b8ba
--- a/pygments/lexers/jvm.py
27b8ba
+++ b/pygments/lexers/jvm.py
27b8ba
@@ -981,7 +981,6 @@ class CeylonLexer(RegexLexer):
27b8ba
             (r'(import)(\s+)', bygroups(Keyword.Namespace, Text), 'import'),
27b8ba
             (r'"(\\\\|\\[^\\]|[^"\\])*"', String),
27b8ba
             (r"'\\.'|'[^\\]'|'\\\{#[0-9a-fA-F]{4}\}'", String.Char),
27b8ba
-            (r'".*``.*``.*"', String.Interpol),
27b8ba
             (r'(\.)([a-z_]\w*)',
27b8ba
              bygroups(Operator, Name.Attribute)),
27b8ba
             (r'[a-zA-Z_]\w*:', Name.Label),
27b8ba
diff --git a/pygments/lexers/matlab.py b/pygments/lexers/matlab.py
27b8ba
index 4823c6a7e..578848623 100644
27b8ba
--- a/pygments/lexers/matlab.py
27b8ba
+++ b/pygments/lexers/matlab.py
27b8ba
@@ -137,7 +137,7 @@ class MatlabLexer(RegexLexer):
27b8ba
             (r'.', Comment.Multiline),
27b8ba
         ],
27b8ba
         'deffunc': [
27b8ba
-            (r'(\s*)(?:(.+)(\s*)(=)(\s*))?(.+)(\()(.*)(\))(\s*)',
27b8ba
+            (r'(\s*)(?:(\S+)(\s*)(=)(\s*))?(.+)(\()(.*)(\))(\s*)',
27b8ba
              bygroups(Whitespace, Text, Whitespace, Punctuation,
27b8ba
                       Whitespace, Name.Function, Punctuation, Text,
27b8ba
                       Punctuation, Whitespace), '#pop'),
27b8ba
@@ -638,7 +638,7 @@ class OctaveLexer(RegexLexer):
27b8ba
             (r"[^']*'", String, '#pop'),
27b8ba
         ],
27b8ba
         'deffunc': [
27b8ba
-            (r'(\s*)(?:(.+)(\s*)(=)(\s*))?(.+)(\()(.*)(\))(\s*)',
27b8ba
+            (r'(\s*)(?:(\S+)(\s*)(=)(\s*))?(.+)(\()(.*)(\))(\s*)',
27b8ba
              bygroups(Whitespace, Text, Whitespace, Punctuation,
27b8ba
                       Whitespace, Name.Function, Punctuation, Text,
27b8ba
                       Punctuation, Whitespace), '#pop'),
27b8ba
@@ -710,7 +710,7 @@ class ScilabLexer(RegexLexer):
27b8ba
             (r'.', String, '#pop'),
27b8ba
         ],
27b8ba
         'deffunc': [
27b8ba
-            (r'(\s*)(?:(.+)(\s*)(=)(\s*))?(.+)(\()(.*)(\))(\s*)',
27b8ba
+            (r'(\s*)(?:(\S+)(\s*)(=)(\s*))?(.+)(\()(.*)(\))(\s*)',
27b8ba
              bygroups(Whitespace, Text, Whitespace, Punctuation,
27b8ba
                       Whitespace, Name.Function, Punctuation, Text,
27b8ba
                       Punctuation, Whitespace), '#pop'),
27b8ba
diff --git a/pygments/lexers/objective.py b/pygments/lexers/objective.py
27b8ba
index 34e4062f6..38ac9bb05 100644
27b8ba
--- a/pygments/lexers/objective.py
27b8ba
+++ b/pygments/lexers/objective.py
27b8ba
@@ -261,11 +261,11 @@ class LogosLexer(ObjectiveCppLexer):
27b8ba
              'logos_classname'),
27b8ba
             (r'(%hook|%group)(\s+)([a-zA-Z$_][\w$]+)',
27b8ba
              bygroups(Keyword, Text, Name.Class)),
27b8ba
-            (r'(%config)(\s*\(\s*)(\w+)(\s*=\s*)(.*?)(\s*\)\s*)',
27b8ba
+            (r'(%config)(\s*\(\s*)(\w+)(\s*=)(.*?)(\)\s*)',
27b8ba
              bygroups(Keyword, Text, Name.Variable, Text, String, Text)),
27b8ba
             (r'(%ctor)(\s*)(\{)', bygroups(Keyword, Text, Punctuation),
27b8ba
              'function'),
27b8ba
-            (r'(%new)(\s*)(\()(\s*.*?\s*)(\))',
27b8ba
+            (r'(%new)(\s*)(\()(.*?)(\))',
27b8ba
              bygroups(Keyword, Text, Keyword, String, Keyword)),
27b8ba
             (r'(\s*)(%end)(\s*)', bygroups(Text, Keyword, Text)),
27b8ba
             inherit,
27b8ba
diff --git a/pygments/lexers/templates.py b/pygments/lexers/templates.py
27b8ba
index 33c06c4c4..5c3346b4c 100644
27b8ba
--- a/pygments/lexers/templates.py
27b8ba
+++ b/pygments/lexers/templates.py
27b8ba
@@ -1405,7 +1405,7 @@ class EvoqueLexer(RegexLexer):
27b8ba
             # see doc for handling first name arg: /directives/evoque/
27b8ba
             # + minor inconsistency: the "name" in e.g. $overlay{name=site_base}
27b8ba
             # should be using(PythonLexer), not passed out as String
27b8ba
-            (r'(\$)(evoque|overlay)(\{(%)?)(\s*[#\w\-"\'.]+[^=,%}]+?)?'
27b8ba
+            (r'(\$)(evoque|overlay)(\{(%)?)(\s*[#\w\-"\'.]+)?'
27b8ba
              r'(.*?)((?(4)%)\})',
27b8ba
              bygroups(Punctuation, Name.Builtin, Punctuation, None,
27b8ba
                       String, using(PythonLexer), Punctuation)),
27b8ba
diff --git a/pygments/lexers/varnish.py b/pygments/lexers/varnish.py
27b8ba
index 23653f7a1..9d358bd7c 100644
27b8ba
--- a/pygments/lexers/varnish.py
27b8ba
+++ b/pygments/lexers/varnish.py
27b8ba
@@ -61,7 +61,7 @@ def analyse_text(text):
27b8ba
              bygroups(Name.Attribute, Operator, Name.Variable.Global, Punctuation)),
27b8ba
             (r'(\.probe)(\s*=\s*)(\{)',
27b8ba
              bygroups(Name.Attribute, Operator, Punctuation), 'probe'),
27b8ba
-            (r'(\.\w+\b)(\s*=\s*)([^;]*)(\s*;)',
27b8ba
+            (r'(\.\w+\b)(\s*=\s*)([^;\s]*)(\s*;)',
27b8ba
              bygroups(Name.Attribute, Operator, using(this), Punctuation)),
27b8ba
             (r'\{', Punctuation, '#push'),
27b8ba
             (r'\}', Punctuation, '#pop'),