Re: Nokogiri security update v1.10.5
James Middlemiss <[email protected]> Mon, 18 Nov 2019 13:11:09 +1100
| Newsgroups | gmane.comp.lang.ruby.general |
|---|---|
| Message-ID | <CANakb-ctYPOeyceAugyvvvPkHGie+Xc4vNrSf5mHv0KdGxQrEQ@mail.gmail.com> |
--===============0441664098== Content-Type: multipart/alternative; boundary="000000000000a3c1870597957661" --000000000000a3c1870597957661 Content-Type: text/plain; charset="UTF-8" Hi, just throwing my 2 cents in here. Upgrading to Nokogiri 1.10.5 for us broke our CircleCI implementation. Fix ended up being to also upgrade: bootsnap (1.4.5) msgpack (1.3.1) On Mon, Nov 18, 2019 at 5:25 AM Mike Dalessio <[email protected]> wrote: > Nokogiri v1.10.5 was released on 2019-10-31. > > This is a security release. > > Maintainers realized, after the release of v1.10.5, that it addresses CVEs > in upstream libxslt rated as "Priority: Medium" and "Priority: Low" by > Canonical, and "NVD Severity: Medium" by Debian. More details are available > below. More details are available below. > > If you're using your distro's system libraries, rather than Nokogiri's > vendored libraries, there's no security need to upgrade at this time, > though you may want to check with your distro whether they've patched this > (Canonical has patched Ubuntu packages). Note that libxslt 1.1.34 addresses > these vulnerabilities. > > Full details about the security update are available in Github Issue #1943 > (https://github.com/sparklemotion/nokogiri/issues/1943). > > Affects: MRI users of Nokogiri's vendored libraries in Nokogiri <= v1.10.4 > > Advice: Upgrade to Nokogiri v1.10.5 or later > > --- > > ## 1.10.5 / 2019-10-31 > > ### Security > > [MRI] Vendored libxslt upgraded to v1.1.34 which addresses three CVEs for > libxslt: > > * CVE-2019-13117 > * CVE-2019-13118 > * CVE-2019-18197 > > More details are available at #1943. > > > ### Dependencies > > * [MRI] vendored libxml2 is updated from 2.9.9 to 2.9.10 > * [MRI] vendored libxslt is updated from 1.1.33 to 1.1.34 > > > > > Unsubscribe: <mailto:[email protected]?subject=unsubscribe> > <http://lists.ruby-lang.org/cgi-bin/mailman/options/ruby-talk> > --000000000000a3c1870597957661 Content-Type: text/html; charset="UTF-8" Content-Transfer-Encoding: quoted-printable <div dir=3D"ltr">Hi, just throwing my 2 cents in here.=C2=A0<br><br>Upgradi= ng to Nokogiri 1.10.5 for us broke our CircleCI implementation.=C2=A0<br><b= r>Fix ended up being to also upgrade:<br>bootsnap (1.4.5)<br>msgpack (1.3.1= )<br><br><br></div><br><div class=3D"gmail_quote"><div dir=3D"ltr" class=3D= "gmail_attr">On Mon, Nov 18, 2019 at 5:25 AM Mike Dalessio <<a href=3D"m= ailto:[email protected]">[email protected]</a>> wrote:<br></= div><blockquote class=3D"gmail_quote" style=3D"margin:0px 0px 0px 0.8ex;bor= der-left:1px solid rgb(204,204,204);padding-left:1ex"><div dir=3D"ltr">Noko= giri v1.10.5 was released on 2019-10-31.<div><br></div><div>This is a secur= ity release.</div><div><br></div><div>Maintainers realized, after the relea= se of v1.10.5, that it addresses CVEs in upstream libxslt rated as "Pr= iority: Medium" and "Priority: Low" by Canonical, and "= NVD Severity: Medium" by Debian. More details are available below. Mor= e details are available below.</div><div><br></div><div><div>If you're = using your distro's system libraries, rather than=C2=A0<span>Nokogiri</= span>'s vendored libraries, there's=C2=A0<span>no</span>=C2=A0secur= ity need to upgrade at this time, though you may want to check with your di= stro whether they've patched this (Canonical has patched Ubuntu package= s). Note that libxslt 1.1.34 addresses these vulnerabilities.</div></div><d= iv><br></div><div>Full details about the security update are available in G= ithub Issue #1943 (<a href=3D"https://github.com/sparklemotion/nokogiri/iss= ues/1943" target=3D"_blank">https://github.com/sparklemotion/nokogiri/issue= s/1943</a>).</div><div><br></div><div>Affects: MRI users of Nokogiri's = vendored libraries in Nokogiri <=3D v1.10.4</div><div><br></div><div>Adv= ice: Upgrade to Nokogiri v1.10.5 or later</div><div><br></div><div>---</div= ><div><br></div><div>## 1.10.5 / 2019-10-31<br><br>### Security<br><br>[MRI= ] Vendored libxslt upgraded to v1.1.34 which addresses three CVEs for libxs= lt:<br><br>* CVE-2019-13117<br>* CVE-2019-13118<br>* CVE-2019-18197<br><br>= More details are available at #1943.<br><br><br>### Dependencies<br><br>* [= MRI] vendored libxml2 is updated from 2.9.9 to 2.9.10<br>* [MRI] vendored l= ibxslt is updated from 1.1.33 to 1.1.34<br><br><br></div><div><br></div></d= iv> <br> Unsubscribe: <mailto:<a href=3D"mailto:[email protected]" = target=3D"_blank">[email protected]</a>?subject=3Dunsubscribe= ><br> <<a href=3D"http://lists.ruby-lang.org/cgi-bin/mailman/options/ruby-talk= " rel=3D"noreferrer" target=3D"_blank">http://lists.ruby-lang.org/cgi-bin/m= ailman/options/ruby-talk</a>><br> </blockquote></div> --000000000000a3c1870597957661-- --===============0441664098== Content-Type: text/plain; charset="us-ascii" MIME-Version: 1.0 Content-Transfer-Encoding: 7bit Content-Disposition: inline Unsubscribe: <mailto:[email protected]?subject=unsubscribe> <http://lists.ruby-lang.org/cgi-bin/mailman/options/ruby-talk> --===============0441664098==--