Add patched version for CVE-2018-1000544 #347
Merged
Add this suggestion to a batch that can be applied as a single commit.
This suggestion is invalid because no changes were made to the code.
Suggestions cannot be applied while the pull request is closed.
Suggestions cannot be applied while viewing a subset of changes.
Only one suggestion per line can be applied in a batch.
Add this suggestion to a batch that can be applied as a single commit.
Applying suggestions on deleted lines is not supported.
You must change the existing code in this line in order to create a valid suggestion.
Outdated suggestions cannot be applied.
This suggestion has been applied or marked resolved.
Suggestions cannot be applied from pending reviews.
Suggestions cannot be applied on multi-line comments.
Suggestions cannot be applied while the pull request is queued to merge.
Suggestion cannot be applied right now. Please check back later.
The rubyzip community is working on CVE-2018-1000544 in the following PR: rubyzip/rubyzip#376
Earlier they worked on a possible fix but then introduced the previously mentioned PR, which disables symlink support.
The gem version got increased from 1.2.1 to 1.2.2. in the PR and some people are already using the branch of the PR. Currently their Travis CI build passes but the coverage check does not, although only the version has been updated in the latest commit.
So far, no objection has been raised regarding the PR and it seems that version 1.2.2 will be the next release, closing the vulnerability.
I have therefore adapted the upcoming version of the rubyzip gem as patched version in the corresponding file for CVE-2018-1000544.
It is clear to me that this PR cannot be pulled immediately and we have to wait for the actual release of the new version of rubyzip. I just wanted to already prepare the adjustment.