Gentoo Websites Logo
Go to: Gentoo Home Documentation Forums Lists Bugs Planet Store Wiki Get Gentoo!
Bug 572946 - <dev-ruby/rails-{3.2.22.1,4.1.14.1,4.2.5.1}: Various vulnerabilities (CVE-2015-{7576,7577,7581},CVE-2016-{0751,0752,0753}),})
Summary: <dev-ruby/rails-{3.2.22.1,4.1.14.1,4.2.5.1}: Various vulnerabilities (CVE-201...
Status: RESOLVED FIXED
Alias: None
Product: Gentoo Security
Classification: Unclassified
Component: Vulnerabilities (show other bugs)
Hardware: All Linux
: Normal normal (vote)
Assignee: Gentoo Security
URL: http://weblog.rubyonrails.org/2016/1/...
Whiteboard: ~3 [noglsa]
Keywords:
Depends on:
Blocks:
 
Reported: 2016-01-26 07:18 UTC by Hans de Graaff
Modified: 2016-05-30 03:55 UTC (History)
2 users (show)

See Also:
Package list:
Runtime testing required: ---


Attachments

Note You need to log in before you can comment on or make changes to this bug.
Description Hans de Graaff gentoo-dev Security 2016-01-26 07:18:44 UTC
Rails 5.0.0.beta1.1, 4.2.5.1, 4.1.14.1, and 3.2.22.1 have been released! These contain the following important security fixes, and it is recommended that users upgrade as soon as possible:

    CVE-2015-7576 Timing attack vulnerability in basic authentication in Action Controller.
    CVE-2016-0751 Possible Object Leak and Denial of Service attack in Action Pack
    CVE-2015-7577 Nested attributes rejection proc bypass in Active Record.
    CVE-2016-0752 Possible Information Leak Vulnerability in Action View
    CVE-2016-0753 Possible Input Validation Circumvention in Active Model
    CVE-2015-7581 Object leak vulnerability for wildcard controller routes in Action Pack
Comment 1 Hans de Graaff gentoo-dev Security 2016-01-26 07:31:46 UTC
Rails 3.2.22.1, 4.1.14.1, and 4.2.5.1 are now in the tree. Cleanup of vulnerable versions in a few days.
Comment 2 Hans de Graaff gentoo-dev Security 2016-01-26 07:34:18 UTC
Rails 4.0.x is no longer maintained upstream and they also did not release patches for this version. It would be best to mask this version for removal, but unfortunately net-analyzer/metasploit still depends on this. cc'ing zerochaos to discuss what to do here.
Comment 3 Hans de Graaff gentoo-dev Security 2016-02-07 17:46:15 UTC
Cleanup done for Rails 3.2, 4.1, and 4.2.

Vulnerable and unpatched Rails 4.0 is still in the tree due to the metasploit dependency.
Comment 4 Aaron Bauman (RETIRED) gentoo-dev 2016-02-17 14:21:21 UTC
Maintainers: please feel free to close this bug once the 4.0 cleanup is complete.  noglsa is required.
Comment 5 Aaron Bauman (RETIRED) gentoo-dev 2016-05-30 03:52:06 UTC
No vulnerable versions in tree.