Gentoo Websites Logo
Go to: Gentoo Home Documentation Forums Lists Bugs Planet Store Wiki Get Gentoo!
Bug 791862 - dev-util/rebar-bin: Missing TLS certificate validation
Summary: dev-util/rebar-bin: Missing TLS certificate validation
Status: RESOLVED FIXED
Alias: None
Product: Gentoo Security
Classification: Unclassified
Component: Vulnerabilities (show other bugs)
Hardware: All Linux
: Normal trivial (vote)
Assignee: Gentoo Security
URL: https://ferd.ca/you-ve-got-to-upgrade...
Whiteboard: ~3 [noglsa]
Keywords: PullRequest
Depends on:
Blocks:
 
Reported: 2021-05-24 17:19 UTC by Matthew Smith
Modified: 2021-05-25 11:46 UTC (History)
3 users (show)

See Also:
Package list:
Runtime testing required: ---


Attachments

Note You need to log in before you can comment on or make changes to this bug.
Description Matthew Smith gentoo-dev 2021-05-24 17:19:21 UTC
A bug introduced in version 3.7.0 of Rebar, an Erlang dependency manager and build tool, broke certificate validation when fetching packages from the hex.pm repository.
Comment 1 Matthew Smith gentoo-dev 2021-05-24 17:21:43 UTC
Sorry for the noise, but I submitted to soon:

Our dev-util/rebar package isn't affected because it was never updated to version 3.

dev-util/rebar-bin is affected, and the fix has landed in versions 3.16.1 and 3.15.2.
Comment 2 Larry the Git Cow gentoo-dev 2021-05-25 11:12:43 UTC
The bug has been referenced in the following commit(s):

https://gitweb.gentoo.org/repo/gentoo.git/commit/?id=ac2512786881302c1e98643515c2c7094cb3cec8

commit ac2512786881302c1e98643515c2c7094cb3cec8
Author:     Matt Smith <matt@offtopica.uk>
AuthorDate: 2021-05-19 06:47:26 +0000
Commit:     Joonas Niilola <juippis@gentoo.org>
CommitDate: 2021-05-25 11:12:35 +0000

    dev-util/rebar-bin: Bump to 3.16.1
    
    Bug: https://bugs.gentoo.org/791862
    Package-Manager: Portage-3.0.18, Repoman-3.0.3
    Signed-off-by: Matt Smith <matt@offtopica.uk>
    Signed-off-by: Joonas Niilola <juippis@gentoo.org>

 dev-util/rebar-bin/Manifest                |  1 +
 dev-util/rebar-bin/rebar-bin-3.16.1.ebuild | 30 ++++++++++++++++++++++++++++++
 2 files changed, 31 insertions(+)
Comment 3 Sam James archtester Gentoo Infrastructure gentoo-dev Security 2021-05-25 11:46:01 UTC
All done, thanks!

(~arch only => trivial 'priority' and noglsa)