Bug 25915 - ruby-rack new security issue CVE-2019-16782
Summary: ruby-rack new security issue CVE-2019-16782
Status: RESOLVED FIXED
Alias: None
Product: Mageia
Classification: Unclassified
Component: Security (show other bugs)
Version: 7
Hardware: All Linux
Priority: Normal normal
Target Milestone: ---
Assignee: Pascal Terjan
QA Contact: Sec team
URL:
Whiteboard:
Keywords:
Depends on: 26688
Blocks:
  Show dependency treegraph
 
Reported: 2019-12-20 21:52 CET by David Walser
Modified: 2020-06-11 02:32 CEST (History)
1 user (show)

See Also:
Source RPM: ruby-rack-2.0.6-1.mga7.src.rpm
CVE:
Status comment: Fixed in Bug 26688


Attachments

Description David Walser 2019-12-20 21:52:59 CET
An advisory has been issued on December 18:
https://www.openwall.com/lists/oss-security/2019/12/18/2

The issue is fixed upstream in 2.0.8.

Mageia 7 is also affected.
David Walser 2019-12-20 21:53:10 CET

Whiteboard: (none) => MGA7TOO

Comment 1 Lewis Smith 2019-12-21 20:28:09 CET
Assigning to Pascal because, in the absence of a registered maintainer, you have done the most recent commits for this package. Hope this is OK.

Assignee: bugsquad => pterjan

David Walser 2020-01-14 17:40:52 CET

Status comment: (none) => Fixed upstream in 2.0.8

Comment 2 David Walser 2020-01-19 17:15:19 CET
Fedora has issued an advisory for this on January 18:
https://lists.fedoraproject.org/archives/list/package-announce@lists.fedoraproject.org/thread/HZXMWILCICQLA2BYSP6I2CRMUG53YBLX/
Comment 3 David Walser 2020-02-20 20:46:31 CET
openSUSE has issued an advisory for this on February 12:
https://lists.opensuse.org/opensuse-updates/2020-02/msg00059.html
Comment 4 David Walser 2020-05-26 23:32:43 CEST
Pascal upgraded Cauldron to 2.2.2 on March 28.

Whiteboard: MGA7TOO => (none)
Version: Cauldron => 7

David Walser 2020-05-26 23:33:28 CEST

Depends on: (none) => 26688

Comment 5 Nicolas Lécureuil 2020-05-27 22:23:19 CEST
updated to version 2.0.8 to fix this bug. 
I kept the patch to fix 26688 too.


ruby-rack-2.0.8-1.mga7

Assignee: pterjan => qa-bugs
CC: (none) => mageia

Comment 6 David Walser 2020-05-27 22:24:39 CEST
We'll assign the newer bug to QA.

Assignee: qa-bugs => pterjan

David Walser 2020-05-27 22:31:43 CEST

Status comment: Fixed upstream in 2.0.8 => Fixed in Bug 26688

Comment 7 David Walser 2020-06-11 02:32:01 CEST
Fixed in:
https://advisories.mageia.org/MGASA-2020-0252.html

Status: NEW => RESOLVED
Resolution: (none) => FIXED


Note You need to log in before you can comment on or make changes to this bug.