Re: Nokogiri security update v1.10.5

James Middlemiss <[email protected]> Mon, 18 Nov 2019 13:11:09 +1100
Newsgroups gmane.comp.lang.ruby.general
Message-ID <CANakb-ctYPOeyceAugyvvvPkHGie+Xc4vNrSf5mHv0KdGxQrEQ@mail.gmail.com>
--===============0441664098==
Content-Type: multipart/alternative; boundary="000000000000a3c1870597957661"

--000000000000a3c1870597957661
Content-Type: text/plain; charset="UTF-8"

Hi, just throwing my 2 cents in here.

Upgrading to Nokogiri 1.10.5 for us broke our CircleCI implementation.

Fix ended up being to also upgrade:
bootsnap (1.4.5)
msgpack (1.3.1)



On Mon, Nov 18, 2019 at 5:25 AM Mike Dalessio <[email protected]>
wrote:

> Nokogiri v1.10.5 was released on 2019-10-31.
>
> This is a security release.
>
> Maintainers realized, after the release of v1.10.5, that it addresses CVEs
> in upstream libxslt rated as "Priority: Medium" and "Priority: Low" by
> Canonical, and "NVD Severity: Medium" by Debian. More details are available
> below. More details are available below.
>
> If you're using your distro's system libraries, rather than Nokogiri's
> vendored libraries, there's no security need to upgrade at this time,
> though you may want to check with your distro whether they've patched this
> (Canonical has patched Ubuntu packages). Note that libxslt 1.1.34 addresses
> these vulnerabilities.
>
> Full details about the security update are available in Github Issue #1943
> (https://github.com/sparklemotion/nokogiri/issues/1943).
>
> Affects: MRI users of Nokogiri's vendored libraries in Nokogiri <= v1.10.4
>
> Advice: Upgrade to Nokogiri v1.10.5 or later
>
> ---
>
> ## 1.10.5 / 2019-10-31
>
> ### Security
>
> [MRI] Vendored libxslt upgraded to v1.1.34 which addresses three CVEs for
> libxslt:
>
> * CVE-2019-13117
> * CVE-2019-13118
> * CVE-2019-18197
>
> More details are available at #1943.
>
>
> ### Dependencies
>
> * [MRI] vendored libxml2 is updated from 2.9.9 to 2.9.10
> * [MRI] vendored libxslt is updated from 1.1.33 to 1.1.34
>
>
>
>
> Unsubscribe: <mailto:[email protected]?subject=unsubscribe>
> <http://lists.ruby-lang.org/cgi-bin/mailman/options/ruby-talk>
>

--000000000000a3c1870597957661
Content-Type: text/html; charset="UTF-8"
Content-Transfer-Encoding: quoted-printable

<div dir=3D"ltr">Hi, just throwing my 2 cents in here.=C2=A0<br><br>Upgradi=
ng to Nokogiri 1.10.5 for us broke our CircleCI implementation.=C2=A0<br><b=
r>Fix ended up being to also upgrade:<br>bootsnap (1.4.5)<br>msgpack (1.3.1=
)<br><br><br></div><br><div class=3D"gmail_quote"><div dir=3D"ltr" class=3D=
"gmail_attr">On Mon, Nov 18, 2019 at 5:25 AM Mike Dalessio &lt;<a href=3D"m=
ailto:[email protected]">[email protected]</a>&gt; wrote:<br></=
div><blockquote class=3D"gmail_quote" style=3D"margin:0px 0px 0px 0.8ex;bor=
der-left:1px solid rgb(204,204,204);padding-left:1ex"><div dir=3D"ltr">Noko=
giri v1.10.5 was released on 2019-10-31.<div><br></div><div>This is a secur=
ity release.</div><div><br></div><div>Maintainers realized, after the relea=
se of v1.10.5, that it addresses CVEs in upstream libxslt rated as &quot;Pr=
iority: Medium&quot; and &quot;Priority: Low&quot; by Canonical, and &quot;=
NVD Severity: Medium&quot; by Debian. More details are available below. Mor=
e details are available below.</div><div><br></div><div><div>If you&#39;re =
using your distro&#39;s system libraries, rather than=C2=A0<span>Nokogiri</=
span>&#39;s vendored libraries, there&#39;s=C2=A0<span>no</span>=C2=A0secur=
ity need to upgrade at this time, though you may want to check with your di=
stro whether they&#39;ve patched this (Canonical has patched Ubuntu package=
s). Note that libxslt 1.1.34 addresses these vulnerabilities.</div></div><d=
iv><br></div><div>Full details about the security update are available in G=
ithub Issue #1943 (<a href=3D"https://github.com/sparklemotion/nokogiri/iss=
ues/1943" target=3D"_blank">https://github.com/sparklemotion/nokogiri/issue=
s/1943</a>).</div><div><br></div><div>Affects: MRI users of Nokogiri&#39;s =
vendored libraries in Nokogiri &lt;=3D v1.10.4</div><div><br></div><div>Adv=
ice: Upgrade to Nokogiri v1.10.5 or later</div><div><br></div><div>---</div=
><div><br></div><div>## 1.10.5 / 2019-10-31<br><br>### Security<br><br>[MRI=
] Vendored libxslt upgraded to v1.1.34 which addresses three CVEs for libxs=
lt:<br><br>* CVE-2019-13117<br>* CVE-2019-13118<br>* CVE-2019-18197<br><br>=
More details are available at #1943.<br><br><br>### Dependencies<br><br>* [=
MRI] vendored libxml2 is updated from 2.9.9 to 2.9.10<br>* [MRI] vendored l=
ibxslt is updated from 1.1.33 to 1.1.34<br><br><br></div><div><br></div></d=
iv>
<br>
Unsubscribe: &lt;mailto:<a href=3D"mailto:[email protected]" =
target=3D"_blank">[email protected]</a>?subject=3Dunsubscribe=
&gt;<br>
&lt;<a href=3D"http://lists.ruby-lang.org/cgi-bin/mailman/options/ruby-talk=
" rel=3D"noreferrer" target=3D"_blank">http://lists.ruby-lang.org/cgi-bin/m=
ailman/options/ruby-talk</a>&gt;<br>
</blockquote></div>

--000000000000a3c1870597957661--

--===============0441664098==
Content-Type: text/plain; charset="us-ascii"
MIME-Version: 1.0
Content-Transfer-Encoding: 7bit
Content-Disposition: inline


Unsubscribe: <mailto:[email protected]?subject=unsubscribe>
<http://lists.ruby-lang.org/cgi-bin/mailman/options/ruby-talk>

--===============0441664098==--