Nokogiri security update v1.10.5

Mike Dalessio <[email protected]> Sun, 17 Nov 2019 13:25:00 -0500
Newsgroups gmane.comp.lang.ruby.general,gmane.comp.security.oss.general
Message-ID <CAGJbjKbpTD1JgrwKo_oNffry77m-XNn1_QGsZvUQWe_nG_3upA@mail.gmail.com>
--===============0607551872==
Content-Type: multipart/alternative; boundary="00000000000096b34c05978ef302"

--00000000000096b34c05978ef302
Content-Type: text/plain; charset="UTF-8"

Nokogiri v1.10.5 was released on 2019-10-31.

This is a security release.

Maintainers realized, after the release of v1.10.5, that it addresses CVEs
in upstream libxslt rated as "Priority: Medium" and "Priority: Low" by
Canonical, and "NVD Severity: Medium" by Debian. More details are available
below. More details are available below.

If you're using your distro's system libraries, rather than Nokogiri's
vendored libraries, there's no security need to upgrade at this time,
though you may want to check with your distro whether they've patched this
(Canonical has patched Ubuntu packages). Note that libxslt 1.1.34 addresses
these vulnerabilities.

Full details about the security update are available in Github Issue #1943 (
https://github.com/sparklemotion/nokogiri/issues/1943).

Affects: MRI users of Nokogiri's vendored libraries in Nokogiri <= v1.10.4

Advice: Upgrade to Nokogiri v1.10.5 or later

---

## 1.10.5 / 2019-10-31

### Security

[MRI] Vendored libxslt upgraded to v1.1.34 which addresses three CVEs for
libxslt:

* CVE-2019-13117
* CVE-2019-13118
* CVE-2019-18197

More details are available at #1943.


### Dependencies

* [MRI] vendored libxml2 is updated from 2.9.9 to 2.9.10
* [MRI] vendored libxslt is updated from 1.1.33 to 1.1.34

--00000000000096b34c05978ef302
Content-Type: text/html; charset="UTF-8"
Content-Transfer-Encoding: quoted-printable

<div dir=3D"ltr">Nokogiri v1.10.5 was released on 2019-10-31.<div><br></div=
><div>This is a security release.</div><div><br></div><div>Maintainers real=
ized, after the release of v1.10.5, that it addresses CVEs in upstream libx=
slt rated as &quot;Priority: Medium&quot; and &quot;Priority: Low&quot; by =
Canonical, and &quot;NVD Severity: Medium&quot; by Debian. More details are=
 available below. More details are available below.</div><div><br></div><di=
v><div>If you&#39;re using your distro&#39;s system libraries, rather than=
=C2=A0<span class=3D"gmail-il">Nokogiri</span>&#39;s vendored libraries, th=
ere&#39;s=C2=A0<span class=3D"gmail-il">no</span>=C2=A0security need to upg=
rade at this time, though you may want to check with your distro whether th=
ey&#39;ve patched this (Canonical has patched Ubuntu packages). Note that l=
ibxslt 1.1.34 addresses these vulnerabilities.</div></div><div><br></div><d=
iv>Full details about the security update are available in Github Issue #19=
43 (<a href=3D"https://github.com/sparklemotion/nokogiri/issues/1943">https=
://github.com/sparklemotion/nokogiri/issues/1943</a>).</div><div><br></div>=
<div>Affects: MRI users of Nokogiri&#39;s vendored libraries in Nokogiri &l=
t;=3D v1.10.4</div><div><br></div><div>Advice: Upgrade to Nokogiri v1.10.5 =
or later</div><div><br></div><div>---</div><div><br></div><div>## 1.10.5 / =
2019-10-31<br><br>### Security<br><br>[MRI] Vendored libxslt upgraded to v1=
.1.34 which addresses three CVEs for libxslt:<br><br>* CVE-2019-13117<br>* =
CVE-2019-13118<br>* CVE-2019-18197<br><br>More details are available at #19=
43.<br><br><br>### Dependencies<br><br>* [MRI] vendored libxml2 is updated =
from 2.9.9 to 2.9.10<br>* [MRI] vendored libxslt is updated from 1.1.33 to =
1.1.34<br><br><br></div><div><br></div></div>

--00000000000096b34c05978ef302--

--===============0607551872==
Content-Type: text/plain; charset="us-ascii"
MIME-Version: 1.0
Content-Transfer-Encoding: 7bit
Content-Disposition: inline


Unsubscribe: <mailto:[email protected]?subject=unsubscribe>
<http://lists.ruby-lang.org/cgi-bin/mailman/options/ruby-talk>

--===============0607551872==--