Gentoo Websites Logo
Go to: Gentoo Home Documentation Forums Lists Bugs Planet Store Wiki Get Gentoo!
Bug 369141 (CVE-2011-0188) - <dev-lang/ruby-1.8.7_p334-r1, dev-lang/ruby-enterprise: Memory allocation error could allow code execution or cause DoS (CVE-2011-0188)
Summary: <dev-lang/ruby-1.8.7_p334-r1, dev-lang/ruby-enterprise: Memory allocation err...
Status: RESOLVED FIXED
Alias: CVE-2011-0188
Product: Gentoo Security
Classification: Unclassified
Component: Vulnerabilities (show other bugs)
Hardware: All Linux
: Normal normal (vote)
Assignee: Gentoo Security
URL: http://svn.ruby-lang.org/cgi-bin/view...
Whiteboard: B2 [glsa]
Keywords:
Depends on:
Blocks:
 
Reported: 2011-05-29 04:15 UTC by Tim Sammut (RETIRED)
Modified: 2014-12-13 19:23 UTC (History)
2 users (show)

See Also:
Package list:
Runtime testing required: ---


Attachments

Note You need to log in before you can comment on or make changes to this bug.
Description Tim Sammut (RETIRED) gentoo-dev 2011-05-29 04:15:41 UTC
http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2011-0188

The VpMemAlloc function in bigdecimal.c in the BigDecimal class in Ruby 1.9.2-p136 and earlier, as used on Apple Mac OS X before 10.6.7 and other platforms, does not properly allocate memory, which allows context-dependent attackers to execute arbitrary code or cause a denial of service (application crash) via vectors involving creation of a large BigDecimal value within a 64-bit process, related to an "integer truncation issue." 

Upstream commit at $URL.
Comment 1 Alex Legler (RETIRED) archtester Gentoo Infrastructure gentoo-dev Security 2011-05-30 15:43:27 UTC
rerating to B2 (special configuration + seldomly used extension)

bump is coming soon
Comment 2 Hans de Graaff gentoo-dev 2011-05-30 17:43:38 UTC
This also needs to be fixed for dev-lang/ruby-enterprise
Comment 3 Alex Legler (RETIRED) archtester Gentoo Infrastructure gentoo-dev Security 2011-05-31 19:13:31 UTC
Arches, please test and mark stable:
=dev-lang/ruby-1.8.7_p334-r1
Target keywords : "alpha amd64 arm hppa ia64 ppc ppc64 s390 sh sparc x86"
Comment 4 Agostino Sarubbo gentoo-dev 2011-05-31 21:05:15 UTC
amd64 ok
Comment 5 Tobias Klausmann gentoo-dev 2011-06-01 09:27:54 UTC
Stable on alpha.
Comment 6 Markos Chandras (RETIRED) gentoo-dev 2011-06-01 15:13:17 UTC
amd64 done. Thanks Agostino
Comment 7 Markus Meier gentoo-dev 2011-06-02 13:32:09 UTC
arm/x86 stable
Comment 8 Brent Baude (RETIRED) gentoo-dev 2011-06-03 15:04:51 UTC
ppc done
Comment 9 Jeroen Roovers (RETIRED) gentoo-dev 2011-06-03 15:13:00 UTC
Stable for HPPA.
Comment 10 Raúl Porcel (RETIRED) gentoo-dev 2011-06-03 17:23:18 UTC
ia64/s390/sh/sparc stable
Comment 11 Kacper Kowalik (Xarthisius) (RETIRED) gentoo-dev 2011-06-07 09:46:49 UTC
ppc64 stable, last arch done
Comment 12 Tim Sammut (RETIRED) gentoo-dev 2011-06-07 13:13:56 UTC
Thanks, everyone. Added to existing GLSA request.
Comment 13 Dion Moult (RETIRED) gentoo-dev 2013-03-24 11:19:22 UTC
A quick note that dev-lang/ruby-enterprise has been treecleaned, so it is no longer relevant to this bug.
Comment 14 GLSAMaker/CVETool Bot gentoo-dev 2014-12-13 19:23:16 UTC
This issue was resolved and addressed in
 GLSA 201412-27 at http://security.gentoo.org/glsa/glsa-201412-27.xml
by GLSA coordinator Sean Amoss (ackle).