Skip to content

Add Ruby CVE 2018-16395 (#358)#359

Merged
reedloden merged 6 commits intorubysec:masterfrom
transoceanic2000:ruby-cve-2018-16395
Oct 18, 2018
Merged

Add Ruby CVE 2018-16395 (#358)#359
reedloden merged 6 commits intorubysec:masterfrom
transoceanic2000:ruby-cve-2018-16395

Conversation

@transoceanic2000
Copy link
Copy Markdown
Contributor

This PR adds CVE 2018-16395 impacting Ruby.

Note that no new preview release of Ruby 2.6.0 has been announced so don't believe there is a patched version that can be indicated at this time.

@peterkeen
Copy link
Copy Markdown
Contributor

peterkeen commented Oct 17, 2018

Is it possible to express the openssl gem workaround as solving this CVE? I don't know if I can update Ruby but I can definitely update openssl. Also, it appears that openssl 2.1.2 hasn't actually been released yet.

@transoceanic2000
Copy link
Copy Markdown
Contributor Author

I don't think there's a way to express that in this file - and it looks like previous issues with OpenSSL are raised against ruby and we don't have OpenSSL as a separate gem that we could record it against.

In later rubies the openssl gem can be independently updated rather than updating Ruby itself.
@transoceanic2000
Copy link
Copy Markdown
Contributor Author

I've added a note about the "upgrade openssl gem separately" workaround from the announcement.

@kuahyeow
Copy link
Copy Markdown

kuahyeow commented Oct 17, 2018 via email

@transoceanic2000
Copy link
Copy Markdown
Contributor Author

Indeed, and no sign in their GitHub of one being about to be created either. Should we take the workaround note out (people can find it from the announcement that we'll be pointing them to anyway)?

@kuahyeow
Copy link
Copy Markdown

kuahyeow commented Oct 17, 2018 via email

Need to hint at this being an option as the "following workarounds" text from the announcement doesn't make sense otherwise.
@transoceanic2000
Copy link
Copy Markdown
Contributor Author

I've updated the workaround text to reflect current situation.

Request review/merge.

@transoceanic2000
Copy link
Copy Markdown
Contributor Author

@reedloden also please could you look at this one and merge if happy - I've re-added the workaround text in the description now that openssl v2.1.2 has been released (I've checked it's visible on rubygems.org).

Comment thread rubies/ruby/CVE-2018-16395.yml Outdated
@reedloden
Copy link
Copy Markdown
Member

Thank you so much! :-)

Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

5 participants