Project

General

Profile

Backport #9193

ruby 1.9.3-p484 still vulnerable to CVE-2013-4287 and CVE-2013-4363 in included rubygems 1.8.23

Added by jeremyevans0 (Jeremy Evans) over 5 years ago. Updated over 5 years ago.

Status:
Closed
Priority:
Normal
[ruby-core:58757]

Description

It appears that ruby 2.0.0-p353 included an update to rubygems 2.0.10 which fixes CVE-2013-4287 and CVE-2013-4363. ruby 1.9.3-p484 did not contain an update to the included rubygems, so it is still vulnerable. ruby 1.9.3 should either be updated to use rubygems 1.8.27 or 1.8.28, or the attached patch should be applied to fix the two CVEs.


Files

rubygems.diff (494 Bytes) rubygems.diff jeremyevans0 (Jeremy Evans), 12/02/2013 09:02 AM
ruby_1_9_3.rubygems.1.8.23.2.patch (2.54 KB) ruby_1_9_3.rubygems.1.8.23.2.patch Complete patch with tests drbrain (Eric Hodel), 12/16/2013 05:12 AM

History

Updated by drbrain (Eric Hodel) over 5 years ago

  • Status changed from Open to Assigned
  • Assignee set to usa (Usaku NAKAMURA)

Updated by usa (Usaku NAKAMURA) over 5 years ago

fixed at r44335.
Thank you for reporting and patching!

Updated by usa (Usaku NAKAMURA) over 5 years ago

  • Status changed from Assigned to Closed

Also available in: Atom PDF