Skip to content
New issue

Have a question about this project? Sign up for a free GitHub account to open an issue and contact its maintainers and the community.

By clicking “Sign up for GitHub”, you agree to our terms of service and privacy statement. We’ll occasionally send you account related emails.

Already on GitHub? Sign in to your account

Add patched version for CVE-2018-1000544 #347

Merged
merged 2 commits into from Aug 31, 2018

Conversation

severinkaelin
Copy link
Contributor

The rubyzip community is working on CVE-2018-1000544 in the following PR: rubyzip/rubyzip#376
Earlier they worked on a possible fix but then introduced the previously mentioned PR, which disables symlink support.

The gem version got increased from 1.2.1 to 1.2.2. in the PR and some people are already using the branch of the PR. Currently their Travis CI build passes but the coverage check does not, although only the version has been updated in the latest commit.

So far, no objection has been raised regarding the PR and it seems that version 1.2.2 will be the next release, closing the vulnerability.

I have therefore adapted the upcoming version of the rubyzip gem as patched version in the corresponding file for CVE-2018-1000544.

It is clear to me that this PR cannot be pulled immediately and we have to wait for the actual release of the new version of rubyzip. I just wanted to already prepare the adjustment.

@klausbadelt
Copy link

Since this seems to affect CI for many (selenium-webdriver etc) would love to see this merged. Thanks @severinkaelin !

@aprescott
Copy link

I don't know anything about the specifics of rubyzip's fix, but rubyzip/rubyzip#376 was just merged and a 1.2.2 release is now available: https://rubygems.org/gems/rubyzip/versions.

Use the fixed version for `patched_versions`
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment
Labels
None yet
Projects
None yet
Development

Successfully merging this pull request may close these issues.

None yet

4 participants