Gentoo Websites Logo
Go to: Gentoo Home Documentation Forums Lists Bugs Planet Store Wiki Get Gentoo!
Bug 418925 - www-apps/redmine: params parsing vulnerability (CVE-2013-0156)
Summary: www-apps/redmine: params parsing vulnerability (CVE-2013-0156)
Status: RESOLVED FIXED
Alias: None
Product: Gentoo Security
Classification: Unclassified
Component: Vulnerabilities (show other bugs)
Hardware: All Linux
: Normal trivial with 4 votes (vote)
Assignee: Gentoo Security
URL: http://www.redmine.org/projects/redmi...
Whiteboard: ~1 [noglsa]
Keywords:
: 413837 (view as bug list)
Depends on: 451078
Blocks:
  Show dependency tree
 
Reported: 2012-06-01 10:38 UTC by Manuel Rüger (RETIRED)
Modified: 2016-05-21 12:07 UTC (History)
16 users (show)

See Also:
Package list:
Runtime testing required: ---


Attachments
redmine version bump (file_418925.txt,8.00 KB, text/plain)
2012-07-10 07:20 UTC, Igor Mikeshin
no flags Details
redmine-1.4.7.ebuild (redmine-1.4.7.ebuild,5.81 KB, text/plain)
2013-01-22 10:44 UTC, Coacher
no flags Details
redmine-2.2.2.ebuild (redmine-2.2.2.ebuild,6.07 KB, text/plain)
2013-01-22 10:47 UTC, Coacher
no flags Details

Note You need to log in before you can comment on or make changes to this bug.
Description Manuel Rüger (RETIRED) gentoo-dev 2012-06-01 10:38:07 UTC
"Redmine 2.0.0 drops Rails 2.3 (which is no longer maintained by the Rails team) in favour of the latest Rails 3 release, and it's now available for download at Rubyforge. New features will come with the next 2.1.0 release.

Efforts have been made to ease the upgrade of existing Redmine plugins but most of them will need a bit of work from their authors in order to be compatible with Rails 3. So if you're using some plugins, you may want to wait before switching to Redmine 2.x."


"Redmine 1.4.2 is a maintenance release that fixes 8 defects, including a compatibility issue with the latest ruby1.9.3 release (patch level 194), several improvements and translations updates. You can review the changes in the Changelog and download this new release at Rubyforge.

Redmine 1.4.x releases stick to Rails 2.3 and will be maintained during the next months for those who won't switch to the forthcoming Redmine 2.0.0 and Rails 3."


Please add them to the tree.
Comment 1 Mark Zhitomirski 2012-06-19 13:41:25 UTC
Redmine 2.0.3 released 2012-06-18 for rails-3.2.6
Comment 2 Igor Mikeshin 2012-07-10 07:20:22 UTC
Created attachment 317754 [details]
redmine version bump

this ebuild works for me to upgrade redmine.

I'm using passenger and got "no such file to load -- /var/lib/redmine/config/environment" after upgrade. Adding this option to vhost helps:
PassengerDefaultUser redmine
Comment 3 Igor Mikeshin 2012-07-11 07:03:53 UTC
if rails>=3.1, 
new redmine need prototype-rails gem
Comment 4 Manuel Rüger (RETIRED) gentoo-dev 2012-11-21 21:25:26 UTC
Redmine 1.4.5 and 2.1.3 were released on Nov 17th 2012

http://www.redmine.org/projects/redmine/wiki/Changelog_1_4
http://www.redmine.org/projects/redmine/wiki/Changelog
Comment 5 Manuel Rüger (RETIRED) gentoo-dev 2012-12-21 02:06:02 UTC
Redmne 2.2.0 released  see http://www.redmine.org/versions/56
Comment 6 Aydar Kamalov 2012-12-21 04:39:50 UTC
I think the maintainers is no longer interested in this project :(
Comment 7 MATSUU Takuto (RETIRED) gentoo-dev 2013-01-07 13:47:25 UTC
sorry for long long long delay.
in cvs now.
Comment 8 David Hallas 2013-01-08 09:56:27 UTC
The ebuild for redmine 2.2.0 doesn't build because it depends on ~dev-ruby/rails-3.2.9:3.2 which is not in portage, but changing it to ~dev-ruby/rails-3.2.10:3.2 fixes the problem.

Also the ebuild depends on >=dev-ruby/rack-openid-0.2.1 but I can't find this package in the tree?

Should I file separate bugs for these?
Comment 9 Coacher 2013-01-09 17:47:56 UTC
I've already filed a bug-report if you fon't mind.
See https://bugs.gentoo.org/show_bug.cgi?id=451078

@mrueg do you care to reopen it with deps including bug above?
Comment 10 Manuel Rüger (RETIRED) gentoo-dev 2013-01-09 18:32:05 UTC
reopening because of unresolved issues.
Comment 11 Coacher 2013-01-11 16:13:38 UTC
A bunch of updates was released a couple of days ago: 1.4.6, 2.1.6, 2.2.1.
2.2.1 has fixes for CVE-2013-0156.
Comment 12 Coacher 2013-01-22 10:44:36 UTC
Created attachment 336464 [details]
redmine-1.4.7.ebuild
Comment 13 Coacher 2013-01-22 10:47:10 UTC
Created attachment 336466 [details]
redmine-2.2.2.ebuild

For this ebuild you need another package rack-openid which is not in tree yet, but you can grab it from here: https://bugs.gentoo.org/show_bug.cgi?id=451078

Or simply grab all the stuff from my local repo at git://bonespirit.org/bonespirit.git
Comment 14 Kevin Bowling 2013-02-03 02:48:38 UTC
This is security critical.
Comment 15 Tom Wijsman (TomWij) (RETIRED) gentoo-dev 2013-02-03 03:06:54 UTC
Re-assigned to security@g.o such that this bug is at least tracked, I didn't spot the CVE code earlier so thanks for mentioning again; as far as I can see it is not clear whether MATSUU wants to continue maintaining the package. Raised importance to a better default as well, so this isn't seen as non-critical.
Comment 16 Sean Amoss (RETIRED) gentoo-dev Security 2013-02-05 14:40:31 UTC
Our Redmine should not have been affected by CVE-2013-0156, but: https://bugs.gentoo.org/show_bug.cgi?id=451078#c2

Matsuu, please bump the ebuild or rev-bump and fix as Hans recommended.
Comment 17 Kevin Bowling 2013-02-12 18:17:31 UTC
More rails CVEs.  Is there any reason to make this depend on a point release?  redmine 2.x has been broken in the tree since it was commited..
Comment 18 Coacher 2013-02-12 18:47:51 UTC
For those who still using redmine 1.4.x be aware that 1.4 branch reached EOL and 1.4.7 is its last release. Here you can find a patch for it to fix CVE-2013-0333:
http://www.redmine.org/news/78
Comment 19 Kevin Bowling 2013-03-02 23:22:09 UTC
This is pretty bad response time, shouldn't you remove it from the tree if nobody can update it?
Comment 20 Manuel Rüger (RETIRED) gentoo-dev 2013-03-24 12:47:33 UTC
http://www.redmine.org/news/81

Redmine 2.3.0 and 2.2.4 released on 2013-03-19
Comment 21 Peter Volkov (RETIRED) gentoo-dev 2013-05-11 09:07:18 UTC
*** Bug 413837 has been marked as a duplicate of this bug. ***
Comment 22 Peter Volkov (RETIRED) gentoo-dev 2013-05-11 21:29:12 UTC
1.4.7 and 2.2.4 are in the tree. Please, test it and report if there are any problems.

@security: there was no stable versions of redmine in the tree. Currently I think bug can be resolved. Vulnerable versions were dropped from the tree.
Comment 23 Jan Matějka (RETIRED) gentoo-dev 2013-08-14 05:22:18 UTC
Can this be closed?

btw. I've just installed 2.2.4 and / renders fine for me.
Comment 24 Chris Reffett (RETIRED) gentoo-dev Security 2013-08-27 01:06:01 UTC
Fixed versions in tree, affected gone. Closing noglsa.