Bug 1457774 - multiple security issues on bundled onigumo
Summary: multiple security issues on bundled onigumo
Keywords:
Status: CLOSED DUPLICATE of bug 1466749
Alias: None
Product: Fedora
Classification: Fedora
Component: ruby
Version: rawhide
Hardware: Unspecified
OS: Unspecified
unspecified
unspecified
Target Milestone: ---
Assignee: Jeroen van Meeuwen
QA Contact: Fedora Extras Quality Assurance
URL:
Whiteboard:
Depends On:
Blocks:
TreeView+ depends on / blocked
 
Reported: 2017-06-01 09:35 UTC by Mamoru TASAKA
Modified: 2017-09-27 11:16 UTC (History)
7 users (show)

Fixed In Version:
Clone Of:
Environment:
Last Closed: 2017-09-27 11:16:08 UTC
Type: Bug
Embargoed:


Attachments (Terms of Use)

Description Mamoru TASAKA 2017-06-01 09:35:13 UTC
Description of problem:
ref: bug 1456725

ruby bundles onigumo, which is modified origuruma of 6.1.2.
Recently, multiple security issues are found on oniguruma through 6.2.0.

Recently multiple security issues were found on oniguruma:
CVE-2017-9226 https://github.com/kkos/oniguruma/issues/55
CVE-2017-9225 https://github.com/kkos/oniguruma/issues/56
CVE-2017-9224 https://github.com/kkos/oniguruma/issues/57
CVE-2017-9227 https://github.com/kkos/oniguruma/issues/58
CVE-2017-9229 https://github.com/kkos/oniguruma/issues/59
CVE-2017-9228 https://github.com/kkos/oniguruma/issues/60
, all of them are fixed in 6.3.0:
https://github.com/kkos/oniguruma/releases

Looks like ruby (onigumo bundled in ruby) is affected by all of these except for CVE-2017-9225.


Version-Release number of selected component (if applicable):
ruby-2.4.1-79.fc27

Comment 1 Jan Kurik 2017-08-15 08:04:25 UTC
This bug appears to have been reported against 'rawhide' during the Fedora 27 development cycle.
Changing version to '27'.

Comment 2 Pavel Valena 2017-09-27 11:01:49 UTC
Ruby 2.4.2 still bundles Onigmo 6.1.1.

https://github.com/ruby/ruby/blob/v2_4_2/include/ruby/onigmo.h

Comment 3 Vít Ondruch 2017-09-27 11:16:08 UTC
This is basically duplicate of bug 1466749 created by security folks. Just FTR, Ruby should not be vulnerable according to upstream. Thanks for reporting.

*** This bug has been marked as a duplicate of bug 1466749 ***


Note You need to log in before you can comment on or make changes to this bug.