First Last Prev Next    No search results available      Search page      Enter new bug
Bug#: 242914
Alias:
Product:
Component:
Status: RESOLVED
Resolution: FIXED
Assigned To: Gentoo Security <security@gentoo.org>
Hardware:
OS:
Version:
Priority:
Severity:
Reporter: Hans de Graaff <graaff@gentoo.org>
Add CC:
CC:
Remove selected CCs
URL:
Summary:
Status Whiteboard:
Keywords:
Flags: Requestee:
 
 
  ()

Filename Description Type Creator Created Size Actions
Create a New Attachment (proposed patch, testcase, etc.) View All

Bug 242914 depends on: Show dependency tree
Bug 242914 blocks:

Additional Comments: (this is where you put emerge --info)


Not eligible to see or edit group visibility for this bug.






View Bug Activity   |   Format For Printing   |   XML   |   Clone This Bug


Description:   Opened: 2008-10-20 18:42 0000
See http://weblog.rubyonrails.org/2008/10/19/response-splitting-risk for a
description of this problem. Currently only 2.0.5 is available as a release.
The page also mentions 2.2.0, but we currently don't have a 2.2.x release in
portage.

------- Comment #1 From Hans de Graaff 2008-10-20 19:38:58 0000 -------
Rails 2.0.5 is now in CVS. I propose to test this version for at least a week
before we stable it.

------- Comment #2 From Alex Legler 2008-10-20 19:43:31 0000 -------
This again [1] is a ruby bug that manifests itself mainly in rails.
Ruby upstream are currently deciding on a patch [2], I expect a decision in the
next few days.

So, ruby would be on the to-do list, too.

[1] similar to bug #236060
[2] http://article.gmane.org/gmane.comp.lang.ruby.core/18709

------- Comment #3 From Robert Buchholz 2008-10-21 14:17:22 0000 -------
(In reply to comment #1)
> Rails 2.0.5 is now in CVS. I propose to test this version for at least a week
> before we stable it.

Sounds good.

------- Comment #4 From Hans de Graaff 2008-10-24 12:22:50 0000 -------
Rails 2.1.2 is now in CVS.

------- Comment #5 From Alex Legler 2009-02-26 16:39:55 0000 -------
Rails is all fixed, no more vulnerable versions in the tree, everything stable.

Ruby upstream obviously have no reason to fix this, it didn't even get any
response on the dev ML.
After talking to rbu, we don't want to derivate from upstream and so don't
patch this into Ruby.

So, do we need a GLSA for rails? I'd say NO.

------- Comment #6 From Raphael Marichez 2009-02-27 22:42:02 0000 -------
as for me, HTTP response splitting and header injection is mainly a vector
attack and has no security impact by itself, but only together with another
application vulnerability. So, unless there is a serious security issue (code
injection, sql injection, denial of service, privelege escalation) caused by
this bug on a standard application, i would say noglsa.

And i'm rerating to B4 and severity is "Minor" for both B3 and B4.

------- Comment #7 From Craig (Security Padawan) 2009-03-07 18:29:33 0000 -------
NO, too. Closing.

First Last Prev Next    No search results available      Search page      Enter new bug