Redmine prior 3.4.4 on 3.4 branch, 3.3.6 on 3.3 branch and 3.2.9 on 3.2 branch has remote vulnerability, which may allow remote attackers to execute arbitrary commands (through the Mercurial adapter)[1][2]. This vulnerability fixed in 3.2.9, 3.3.6 and 3.4.4 versions. Pull request on the way. [1] https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2017-18026 [2] http://www.redmine.org/projects/redmine/wiki/Security_Advisories
PR https://github.com/gentoo/gentoo/pull/6520
CVE-2017-18026 (https://nvd.nist.gov/vuln/detail/CVE-2017-18026): Redmine before 3.2.9, 3.3.x before 3.3.6, and 3.4.x before 3.4.4 does not block the --config and --debugger flags to the Mercurial hg program, which allows remote attackers to execute arbitrary commands (through the Mercurial adapter) via vectors involving a branch whose name begins with a --config= or --debugger= substring, a related issue to CVE-2017-17536.
The bug has been referenced in the following commit(s): https://gitweb.gentoo.org/repo/gentoo.git/commit/?id=6edaba168aac7d45d58d0c4797c7a7a3d438cd88 commit 6edaba168aac7d45d58d0c4797c7a7a3d438cd88 Author: Azamat H. Hackimov <azamat.hackimov@gmail.com> AuthorDate: 2018-01-25 23:43:46 +0000 Commit: Thomas Deutschmann <whissi@gentoo.org> CommitDate: 2018-01-26 00:19:53 +0000 www-apps/redmine: bump to 3.2.9, 3.3.6, 3.4.3 Closes remote vulnerability CVE-2017-18026 (#644314). Closes: https://github.com/gentoo/gentoo/pull/6520 Bug: https://bugs.gentoo.org/644314 Package-Manager: Portage-2.3.13, Repoman-2.3.3 www-apps/redmine/Manifest | 6 +++--- www-apps/redmine/{redmine-3.2.8.ebuild => redmine-3.2.9.ebuild} | 2 +- www-apps/redmine/{redmine-3.3.5.ebuild => redmine-3.3.6.ebuild} | 2 +- www-apps/redmine/{redmine-3.4.3.ebuild => redmine-3.4.4.ebuild} | 4 ++-- 4 files changed, 7 insertions(+), 7 deletions(-)}