Gentoo Websites Logo
Go to: Gentoo Home Documentation Forums Lists Bugs Planet Store Wiki Get Gentoo!
Bug 700390 - =dev-ruby/nokogiri-1.10.5 version bump
Summary: =dev-ruby/nokogiri-1.10.5 version bump
Status: RESOLVED FIXED
Alias: None
Product: Gentoo Linux
Classification: Unclassified
Component: Current packages (show other bugs)
Hardware: All Linux
: Normal normal (vote)
Assignee: Gentoo Ruby Team
URL:
Whiteboard:
Keywords:
Depends on:
Blocks:
 
Reported: 2019-11-17 20:25 UTC by Jeroen Roovers (RETIRED)
Modified: 2020-09-14 07:33 UTC (History)
1 user (show)

See Also:
Package list:
Runtime testing required: ---


Attachments

Note You need to log in before you can comment on or make changes to this bug.
Description Jeroen Roovers (RETIRED) gentoo-dev 2019-11-17 20:25:59 UTC
"Nokogiri v1.10.5 was released on 2019-10-31."
Comment 1 Anton Bolshakov 2020-09-12 03:22:49 UTC
Name: nokogiri
Version: 1.10.4
Advisory: CVE-2020-7595
Criticality: High
URL: https://github.com/sparklemotion/nokogiri/issues/1992
Title: libxml2 2.9.10 has an infinite loop in a certain end-of-file situation
Solution: upgrade to >= 1.10.8

Name: nokogiri
Version: 1.10.4
Advisory: CVE-2019-13117
Criticality: Unknown
URL: https://github.com/sparklemotion/nokogiri/issues/1943
Title: Nokogiri gem, via libxslt, is affected by multiple vulnerabilities
Solution: upgrade to >= 1.10.5
Comment 2 Sam James archtester Gentoo Infrastructure gentoo-dev Security 2020-09-12 03:30:55 UTC
(In reply to Anton Bolshakov from comment #1)
> Name: nokogiri
> Version: 1.10.4
> Advisory: CVE-2020-7595
> Criticality: High
> URL: https://github.com/sparklemotion/nokogiri/issues/1992
> Title: libxml2 2.9.10 has an infinite loop in a certain end-of-file situation
> Solution: upgrade to >= 1.10.8
> 
> Name: nokogiri
> Version: 1.10.4
> Advisory: CVE-2019-13117
> Criticality: Unknown
> URL: https://github.com/sparklemotion/nokogiri/issues/1943
> Title: Nokogiri gem, via libxslt, is affected by multiple vulnerabilities
> Solution: upgrade to >= 1.10.5

File security bugs so we don't lose track of 'em, but here libxml and libxslt aren't vendored, so these were fixed by the blocker bug (yay).

It's not actually a 'depends on' anymore because the bump & stabilisation is done, so I'll move that.

We also have 1.10.10 since https://gitweb.gentoo.org/repo/gentoo.git/commit/?id=ebccde55faac914ea96b744a9723b2ee542f2152 (15th August) so I'm going to tentatively close.

Thanks for the comment btw.
Comment 3 Hans de Graaff gentoo-dev Security 2020-09-14 07:33:31 UTC
FYI there is now bug 742458 to stable nokogiri 1.10.10.