Re: Nokogiri security update v1.10.5

Mike Dalessio <[email protected]> Sun, 17 Nov 2019 21:31:27 -0500
Newsgroups gmane.comp.lang.ruby.general
Message-ID <CAGJbjKZa827ScfAYi9jzLP3dWr2ARqJicaULLuPr10c9BOFJFw@mail.gmail.com>
--===============1662620425==
Content-Type: multipart/alternative; boundary="00000000000050670e059795bf9e"

--00000000000050670e059795bf9e
Content-Type: text/plain; charset="UTF-8"

Hi James,

Can I ask that you please open a GitHub issue on Nokogiri? Without any
accompanying information I don't know where to start to diagnose what
you're seeing.


On Sun, Nov 17, 2019, 9:11 PM James Middlemiss <[email protected]>
wrote:

> Hi, just throwing my 2 cents in here.
>
> Upgrading to Nokogiri 1.10.5 for us broke our CircleCI implementation.
>
> Fix ended up being to also upgrade:
> bootsnap (1.4.5)
> msgpack (1.3.1)
>
>
>
> On Mon, Nov 18, 2019 at 5:25 AM Mike Dalessio <[email protected]>
> wrote:
>
>> Nokogiri v1.10.5 was released on 2019-10-31.
>>
>> This is a security release.
>>
>> Maintainers realized, after the release of v1.10.5, that it addresses
>> CVEs in upstream libxslt rated as "Priority: Medium" and "Priority: Low" by
>> Canonical, and "NVD Severity: Medium" by Debian. More details are available
>> below. More details are available below.
>>
>> If you're using your distro's system libraries, rather than Nokogiri's
>> vendored libraries, there's no security need to upgrade at this time,
>> though you may want to check with your distro whether they've patched this
>> (Canonical has patched Ubuntu packages). Note that libxslt 1.1.34 addresses
>> these vulnerabilities.
>>
>> Full details about the security update are available in Github Issue
>> #1943 (https://github.com/sparklemotion/nokogiri/issues/1943).
>>
>> Affects: MRI users of Nokogiri's vendored libraries in Nokogiri <= v1.10.4
>>
>> Advice: Upgrade to Nokogiri v1.10.5 or later
>>
>> ---
>>
>> ## 1.10.5 / 2019-10-31
>>
>> ### Security
>>
>> [MRI] Vendored libxslt upgraded to v1.1.34 which addresses three CVEs for
>> libxslt:
>>
>> * CVE-2019-13117
>> * CVE-2019-13118
>> * CVE-2019-18197
>>
>> More details are available at #1943.
>>
>>
>> ### Dependencies
>>
>> * [MRI] vendored libxml2 is updated from 2.9.9 to 2.9.10
>> * [MRI] vendored libxslt is updated from 1.1.33 to 1.1.34
>>
>>
>>
>>
>> Unsubscribe: <mailto:[email protected]?subject=unsubscribe>
>> <http://lists.ruby-lang.org/cgi-bin/mailman/options/ruby-talk>
>>
>
> Unsubscribe: <mailto:[email protected]?subject=unsubscribe>
> <http://lists.ruby-lang.org/cgi-bin/mailman/options/ruby-talk>
>

--00000000000050670e059795bf9e
Content-Type: text/html; charset="UTF-8"
Content-Transfer-Encoding: quoted-printable

<div dir=3D"auto"><div>Hi James,</div><div dir=3D"auto"><br></div><div dir=
=3D"auto">Can I ask that you please open a GitHub issue on Nokogiri? Withou=
t any accompanying information I don&#39;t know where to start to diagnose =
what you&#39;re seeing.<br><br><br><div class=3D"gmail_quote" dir=3D"auto">=
<div dir=3D"ltr" class=3D"gmail_attr">On Sun, Nov 17, 2019, 9:11 PM James M=
iddlemiss &lt;<a href=3D"mailto:[email protected]">james.o.middl=
[email protected]</a>&gt; wrote:<br></div><blockquote class=3D"gmail_quote" s=
tyle=3D"margin:0 0 0 .8ex;border-left:1px #ccc solid;padding-left:1ex"><div=
 dir=3D"ltr">Hi, just throwing my 2 cents in here.=C2=A0<br><br>Upgrading t=
o Nokogiri 1.10.5 for us broke our CircleCI implementation.=C2=A0<br><br>Fi=
x ended up being to also upgrade:<br>bootsnap (1.4.5)<br>msgpack (1.3.1)<br=
><br><br></div><br><div class=3D"gmail_quote"><div dir=3D"ltr" class=3D"gma=
il_attr">On Mon, Nov 18, 2019 at 5:25 AM Mike Dalessio &lt;<a href=3D"mailt=
o:[email protected]" target=3D"_blank" rel=3D"noreferrer">mike.daless=
[email protected]</a>&gt; wrote:<br></div><blockquote class=3D"gmail_quote" styl=
e=3D"margin:0px 0px 0px 0.8ex;border-left:1px solid rgb(204,204,204);paddin=
g-left:1ex"><div dir=3D"ltr">Nokogiri v1.10.5 was released on 2019-10-31.<d=
iv><br></div><div>This is a security release.</div><div><br></div><div>Main=
tainers realized, after the release of v1.10.5, that it addresses CVEs in u=
pstream libxslt rated as &quot;Priority: Medium&quot; and &quot;Priority: L=
ow&quot; by Canonical, and &quot;NVD Severity: Medium&quot; by Debian. More=
 details are available below. More details are available below.</div><div><=
br></div><div><div>If you&#39;re using your distro&#39;s system libraries, =
rather than=C2=A0<span>Nokogiri</span>&#39;s vendored libraries, there&#39;=
s=C2=A0<span>no</span>=C2=A0security need to upgrade at this time, though y=
ou may want to check with your distro whether they&#39;ve patched this (Can=
onical has patched Ubuntu packages). Note that libxslt 1.1.34 addresses the=
se vulnerabilities.</div></div><div><br></div><div>Full details about the s=
ecurity update are available in Github Issue #1943 (<a href=3D"https://gith=
ub.com/sparklemotion/nokogiri/issues/1943" target=3D"_blank" rel=3D"norefer=
rer">https://github.com/sparklemotion/nokogiri/issues/1943</a>).</div><div>=
<br></div><div>Affects: MRI users of Nokogiri&#39;s vendored libraries in N=
okogiri &lt;=3D v1.10.4</div><div><br></div><div>Advice: Upgrade to Nokogir=
i v1.10.5 or later</div><div><br></div><div>---</div><div><br></div><div>##=
 1.10.5 / 2019-10-31<br><br>### Security<br><br>[MRI] Vendored libxslt upgr=
aded to v1.1.34 which addresses three CVEs for libxslt:<br><br>* CVE-2019-1=
3117<br>* CVE-2019-13118<br>* CVE-2019-18197<br><br>More details are availa=
ble at #1943.<br><br><br>### Dependencies<br><br>* [MRI] vendored libxml2 i=
s updated from 2.9.9 to 2.9.10<br>* [MRI] vendored libxslt is updated from =
1.1.33 to 1.1.34<br><br><br></div><div><br></div></div>
<br>
Unsubscribe: &lt;mailto:<a href=3D"mailto:[email protected]" =
target=3D"_blank" rel=3D"noreferrer">[email protected]</a>?su=
bject=3Dunsubscribe&gt;<br>
&lt;<a href=3D"http://lists.ruby-lang.org/cgi-bin/mailman/options/ruby-talk=
" rel=3D"noreferrer noreferrer" target=3D"_blank">http://lists.ruby-lang.or=
g/cgi-bin/mailman/options/ruby-talk</a>&gt;<br>
</blockquote></div>
<br>
Unsubscribe: &lt;mailto:<a href=3D"mailto:[email protected]" =
target=3D"_blank" rel=3D"noreferrer">[email protected]</a>?su=
bject=3Dunsubscribe&gt;<br>
&lt;<a href=3D"http://lists.ruby-lang.org/cgi-bin/mailman/options/ruby-talk=
" rel=3D"noreferrer noreferrer" target=3D"_blank">http://lists.ruby-lang.or=
g/cgi-bin/mailman/options/ruby-talk</a>&gt;<br>
</blockquote></div></div></div>

--00000000000050670e059795bf9e--

--===============1662620425==
Content-Type: text/plain; charset="us-ascii"
MIME-Version: 1.0
Content-Transfer-Encoding: 7bit
Content-Disposition: inline


Unsubscribe: <mailto:[email protected]?subject=unsubscribe>
<http://lists.ruby-lang.org/cgi-bin/mailman/options/ruby-talk>

--===============1662620425==--