Bug 13659 - ruby-activerecord new security issue CVE-2014-3483
Summary: ruby-activerecord new security issue CVE-2014-3483
Status: RESOLVED FIXED
Alias: None
Product: Mageia
Classification: Unclassified
Component: Security (show other bugs)
Version: 4
Hardware: i586 Linux
Priority: Normal normal
Target Milestone: ---
Assignee: Pascal Terjan
QA Contact: Sec team
URL: http://lwn.net/Vulnerabilities/605460/
Whiteboard:
Keywords:
Depends on: 13339
Blocks:
  Show dependency treegraph
 
Reported: 2014-07-02 21:43 CEST by David Walser
Modified: 2014-07-26 22:32 CEST (History)
0 users

See Also:
Source RPM: ruby-activerecord-4.1.2-1.mga5.src.rpm
CVE:
Status comment:


Attachments

Description David Walser 2014-07-02 21:43:31 CEST
A security issue fixed upstream has been announced today (July 2):
http://openwall.com/lists/oss-security/2014/07/02/5

The issue is fixed upstream in versions 4.0.7 and 4.1.3.

This should be updated along with the rest of the packages in the rails suite, which would also fix Bug 13339.

Reproducible: 

Steps to Reproduce:
David Walser 2014-07-02 21:43:42 CEST

Whiteboard: (none) => MGA4TOO

David Walser 2014-07-02 21:43:52 CEST

Depends on: (none) => 13339

Comment 1 Pascal Terjan 2014-07-02 23:14:57 CEST
4.1.3 submitted to cauldron.
David Walser 2014-07-02 23:18:37 CEST

Whiteboard: MGA4TOO => (none)
Version: Cauldron => 4

Comment 2 Pascal Terjan 2014-07-02 23:46:24 CEST
4.0.7 submitted to 4/updates_testing
Comment 3 David Walser 2014-07-03 00:34:43 CEST
Thanks Pascal!  Unfortunately it was just announced that the CVE fixed caused a regression.  Patches against 4.0.7 and 4.1.3 are posted here:
http://seclists.org/oss-sec/2014/q3/10
Comment 4 Pascal Terjan 2014-07-03 00:48:19 CEST
Submitted patched versions
Comment 5 David Walser 2014-07-03 01:01:14 CEST
Thanks again Pascal!

Upstream has released 4.1.4 and 4.0.8 to include the regression fix patches:
http://weblog.rubyonrails.org/2014/7/2/Rails_4_0_8_and_4_1_4_have_been_released/

We can go with what you've already built, or you can update it again.  I'll leave that up to you.  We'll handle the update with QA in Bug 13339.

I'll wait until tomorrow to assign to QA.
Comment 6 Pascal Terjan 2014-07-03 01:27:11 CEST
4.1.4 and 4.0.8 submitted
Comment 7 David Walser 2014-07-03 04:27:07 CEST
Thank you so much Pascal!  Sorry you had to do it three times :o(
Comment 8 David Walser 2014-07-17 21:38:13 CEST
RedHat has issued an advisory for this on July 14:
https://rhn.redhat.com/errata/RHSA-2014-0877.html

URL: (none) => http://lwn.net/Vulnerabilities/605460/

Comment 9 David Walser 2014-07-26 22:32:14 CEST
Fixed:
http://advisories.mageia.org/MGASA-2014-0303.html

Status: NEW => RESOLVED
Resolution: (none) => FIXED


Note You need to log in before you can comment on or make changes to this bug.