An issue was discovered in StringIO 3.0.1, as distributed in Ruby 3.0.x through 3.0.6 and 3.1.x through 3.1.4. The ungetbyte and ungetc methods on a StringIO can read past the end of a string, and a subsequent call to StringIO.gets may return the memory value. This vulnerability is not affected StringIO 3.0.3 and later, and Ruby 3.2.x and later.
Created alexandria tracking bugs for this issue: Affects: fedora-all [bug 2270762] Created ruby:3.1/rubygem-pg tracking bugs for this issue: Affects: fedora-38 [bug 2270757] Created rubygem-ammeter tracking bugs for this issue: Affects: fedora-all [bug 2270763] Created rubygem-domain_name tracking bugs for this issue: Affects: fedora-38 [bug 2270759] Created rubygem-haml tracking bugs for this issue: Affects: fedora-all [bug 2270764] Created rubygem-highline tracking bugs for this issue: Affects: epel-8 [bug 2270755] Created rubygem-http-cookie tracking bugs for this issue: Affects: fedora-all [bug 2270765] Created rubygem-jquery-rails tracking bugs for this issue: Affects: fedora-38 [bug 2270760] Created rubygem-marc tracking bugs for this issue: Affects: fedora-all [bug 2270766] Created rubygem-mechanize tracking bugs for this issue: Affects: fedora-38 [bug 2270761] Created rubygem-minitest-around tracking bugs for this issue: Affects: fedora-all [bug 2270767] Created rubygem-net-http-persistent tracking bugs for this issue: Affects: fedora-all [bug 2270768] Created rubygem-pg tracking bugs for this issue: Affects: fedora-all [bug 2270769] Created rubygem-power_assert tracking bugs for this issue: Affects: fedora-all [bug 2270770] Created rubygem-rdoc tracking bugs for this issue: Affects: fedora-all [bug 2270771] Created rubygem-shindo tracking bugs for this issue: Affects: fedora-all [bug 2270773] Created rubygem-shoulda-context tracking bugs for this issue: Affects: fedora-all [bug 2270774] Created rubygem-sinatra tracking bugs for this issue: Affects: epel-7 [bug 2270754] Created rubygem-tins tracking bugs for this issue: Affects: fedora-all [bug 2270775] Created rubygem-webmock tracking bugs for this issue: Affects: fedora-all [bug 2270776] Created whatweb tracking bugs for this issue: Affects: epel-8 [bug 2270756] Affects: fedora-all [bug 2270753]
So would you please stop filing bugs of this kind without consideration? I don't think we are expected to cope with these bugs even if "Disclaimer" is expressed.
Created alexandria tracking bugs for this issue: Affects: fedora-38 [bug 2277062] Affects: fedora-39 [bug 2277078] Created ruby tracking bugs for this issue: Affects: fedora-38 [bug 2277058] Affects: fedora-39 [bug 2277060] Affects: fedora-40 [bug 2277061] Created ruby:3.1/ruby tracking bugs for this issue: Affects: fedora-38 [bug 2277059] Created rubygem-ammeter tracking bugs for this issue: Affects: fedora-38 [bug 2277063] Affects: fedora-39 [bug 2277079] Created rubygem-haml tracking bugs for this issue: Affects: fedora-38 [bug 2277064] Affects: fedora-39 [bug 2277080] Created rubygem-http-cookie tracking bugs for this issue: Affects: fedora-38 [bug 2277065] Affects: fedora-39 [bug 2277081] Created rubygem-marc tracking bugs for this issue: Affects: fedora-38 [bug 2277066] Affects: fedora-39 [bug 2277082] Created rubygem-minitest-around tracking bugs for this issue: Affects: fedora-38 [bug 2277067] Affects: fedora-39 [bug 2277083] Created rubygem-net-http-persistent tracking bugs for this issue: Affects: fedora-38 [bug 2277068] Affects: fedora-39 [bug 2277084] Created rubygem-pdfkit tracking bugs for this issue: Affects: fedora-38 [bug 2277069] Affects: fedora-39 [bug 2277085] Affects: fedora-all [bug 2277056] Created rubygem-pg tracking bugs for this issue: Affects: fedora-38 [bug 2277070] Affects: fedora-39 [bug 2277086] Created rubygem-power_assert tracking bugs for this issue: Affects: fedora-38 [bug 2277071] Affects: fedora-39 [bug 2277087] Created rubygem-rdoc tracking bugs for this issue: Affects: fedora-38 [bug 2277072] Affects: fedora-39 [bug 2277088] Created rubygem-shindo tracking bugs for this issue: Affects: fedora-38 [bug 2277073] Affects: fedora-39 [bug 2277089] Created rubygem-shoulda-context tracking bugs for this issue: Affects: fedora-38 [bug 2277074] Affects: fedora-39 [bug 2277090] Created rubygem-tins tracking bugs for this issue: Affects: fedora-38 [bug 2277075] Affects: fedora-39 [bug 2277091] Created rubygem-webmock tracking bugs for this issue: Affects: fedora-38 [bug 2277076] Affects: fedora-39 [bug 2277092] Created whatweb tracking bugs for this issue: Affects: fedora-38 [bug 2277077] Affects: fedora-39 [bug 2277093]
@saroy there was risen concern with the Fedora trackers and you have just filled more. What is the point of the trackers? That some project is using vulnerable StringIO?
(In reply to Vít Ondruch from comment #7) > @saroy there was risen concern with the Fedora trackers and you > have just filled more. What is the point of the trackers? That some project > is using vulnerable StringIO? For others who might be watching this ticket, I cannot promise any fix, but at least my concern was heard. I was provided with some details of output of internal tooling and links to the source code.