Re: Nokogiri security update v1.10.5
Mike Dalessio <[email protected]> Sun, 17 Nov 2019 21:31:27 -0500
| Newsgroups | gmane.comp.lang.ruby.general |
|---|---|
| Message-ID | <CAGJbjKZa827ScfAYi9jzLP3dWr2ARqJicaULLuPr10c9BOFJFw@mail.gmail.com> |
--===============1662620425== Content-Type: multipart/alternative; boundary="00000000000050670e059795bf9e" --00000000000050670e059795bf9e Content-Type: text/plain; charset="UTF-8" Hi James, Can I ask that you please open a GitHub issue on Nokogiri? Without any accompanying information I don't know where to start to diagnose what you're seeing. On Sun, Nov 17, 2019, 9:11 PM James Middlemiss <[email protected]> wrote: > Hi, just throwing my 2 cents in here. > > Upgrading to Nokogiri 1.10.5 for us broke our CircleCI implementation. > > Fix ended up being to also upgrade: > bootsnap (1.4.5) > msgpack (1.3.1) > > > > On Mon, Nov 18, 2019 at 5:25 AM Mike Dalessio <[email protected]> > wrote: > >> Nokogiri v1.10.5 was released on 2019-10-31. >> >> This is a security release. >> >> Maintainers realized, after the release of v1.10.5, that it addresses >> CVEs in upstream libxslt rated as "Priority: Medium" and "Priority: Low" by >> Canonical, and "NVD Severity: Medium" by Debian. More details are available >> below. More details are available below. >> >> If you're using your distro's system libraries, rather than Nokogiri's >> vendored libraries, there's no security need to upgrade at this time, >> though you may want to check with your distro whether they've patched this >> (Canonical has patched Ubuntu packages). Note that libxslt 1.1.34 addresses >> these vulnerabilities. >> >> Full details about the security update are available in Github Issue >> #1943 (https://github.com/sparklemotion/nokogiri/issues/1943). >> >> Affects: MRI users of Nokogiri's vendored libraries in Nokogiri <= v1.10.4 >> >> Advice: Upgrade to Nokogiri v1.10.5 or later >> >> --- >> >> ## 1.10.5 / 2019-10-31 >> >> ### Security >> >> [MRI] Vendored libxslt upgraded to v1.1.34 which addresses three CVEs for >> libxslt: >> >> * CVE-2019-13117 >> * CVE-2019-13118 >> * CVE-2019-18197 >> >> More details are available at #1943. >> >> >> ### Dependencies >> >> * [MRI] vendored libxml2 is updated from 2.9.9 to 2.9.10 >> * [MRI] vendored libxslt is updated from 1.1.33 to 1.1.34 >> >> >> >> >> Unsubscribe: <mailto:[email protected]?subject=unsubscribe> >> <http://lists.ruby-lang.org/cgi-bin/mailman/options/ruby-talk> >> > > Unsubscribe: <mailto:[email protected]?subject=unsubscribe> > <http://lists.ruby-lang.org/cgi-bin/mailman/options/ruby-talk> > --00000000000050670e059795bf9e Content-Type: text/html; charset="UTF-8" Content-Transfer-Encoding: quoted-printable <div dir=3D"auto"><div>Hi James,</div><div dir=3D"auto"><br></div><div dir= =3D"auto">Can I ask that you please open a GitHub issue on Nokogiri? Withou= t any accompanying information I don't know where to start to diagnose = what you're seeing.<br><br><br><div class=3D"gmail_quote" dir=3D"auto">= <div dir=3D"ltr" class=3D"gmail_attr">On Sun, Nov 17, 2019, 9:11 PM James M= iddlemiss <<a href=3D"mailto:[email protected]">james.o.middl= [email protected]</a>> wrote:<br></div><blockquote class=3D"gmail_quote" s= tyle=3D"margin:0 0 0 .8ex;border-left:1px #ccc solid;padding-left:1ex"><div= dir=3D"ltr">Hi, just throwing my 2 cents in here.=C2=A0<br><br>Upgrading t= o Nokogiri 1.10.5 for us broke our CircleCI implementation.=C2=A0<br><br>Fi= x ended up being to also upgrade:<br>bootsnap (1.4.5)<br>msgpack (1.3.1)<br= ><br><br></div><br><div class=3D"gmail_quote"><div dir=3D"ltr" class=3D"gma= il_attr">On Mon, Nov 18, 2019 at 5:25 AM Mike Dalessio <<a href=3D"mailt= o:[email protected]" target=3D"_blank" rel=3D"noreferrer">mike.daless= [email protected]</a>> wrote:<br></div><blockquote class=3D"gmail_quote" styl= e=3D"margin:0px 0px 0px 0.8ex;border-left:1px solid rgb(204,204,204);paddin= g-left:1ex"><div dir=3D"ltr">Nokogiri v1.10.5 was released on 2019-10-31.<d= iv><br></div><div>This is a security release.</div><div><br></div><div>Main= tainers realized, after the release of v1.10.5, that it addresses CVEs in u= pstream libxslt rated as "Priority: Medium" and "Priority: L= ow" by Canonical, and "NVD Severity: Medium" by Debian. More= details are available below. More details are available below.</div><div><= br></div><div><div>If you're using your distro's system libraries, = rather than=C2=A0<span>Nokogiri</span>'s vendored libraries, there'= s=C2=A0<span>no</span>=C2=A0security need to upgrade at this time, though y= ou may want to check with your distro whether they've patched this (Can= onical has patched Ubuntu packages). Note that libxslt 1.1.34 addresses the= se vulnerabilities.</div></div><div><br></div><div>Full details about the s= ecurity update are available in Github Issue #1943 (<a href=3D"https://gith= ub.com/sparklemotion/nokogiri/issues/1943" target=3D"_blank" rel=3D"norefer= rer">https://github.com/sparklemotion/nokogiri/issues/1943</a>).</div><div>= <br></div><div>Affects: MRI users of Nokogiri's vendored libraries in N= okogiri <=3D v1.10.4</div><div><br></div><div>Advice: Upgrade to Nokogir= i v1.10.5 or later</div><div><br></div><div>---</div><div><br></div><div>##= 1.10.5 / 2019-10-31<br><br>### Security<br><br>[MRI] Vendored libxslt upgr= aded to v1.1.34 which addresses three CVEs for libxslt:<br><br>* CVE-2019-1= 3117<br>* CVE-2019-13118<br>* CVE-2019-18197<br><br>More details are availa= ble at #1943.<br><br><br>### Dependencies<br><br>* [MRI] vendored libxml2 i= s updated from 2.9.9 to 2.9.10<br>* [MRI] vendored libxslt is updated from = 1.1.33 to 1.1.34<br><br><br></div><div><br></div></div> <br> Unsubscribe: <mailto:<a href=3D"mailto:[email protected]" = target=3D"_blank" rel=3D"noreferrer">[email protected]</a>?su= bject=3Dunsubscribe><br> <<a href=3D"http://lists.ruby-lang.org/cgi-bin/mailman/options/ruby-talk= " rel=3D"noreferrer noreferrer" target=3D"_blank">http://lists.ruby-lang.or= g/cgi-bin/mailman/options/ruby-talk</a>><br> </blockquote></div> <br> Unsubscribe: <mailto:<a href=3D"mailto:[email protected]" = target=3D"_blank" rel=3D"noreferrer">[email protected]</a>?su= bject=3Dunsubscribe><br> <<a href=3D"http://lists.ruby-lang.org/cgi-bin/mailman/options/ruby-talk= " rel=3D"noreferrer noreferrer" target=3D"_blank">http://lists.ruby-lang.or= g/cgi-bin/mailman/options/ruby-talk</a>><br> </blockquote></div></div></div> --00000000000050670e059795bf9e-- --===============1662620425== Content-Type: text/plain; charset="us-ascii" MIME-Version: 1.0 Content-Transfer-Encoding: 7bit Content-Disposition: inline Unsubscribe: <mailto:[email protected]?subject=unsubscribe> <http://lists.ruby-lang.org/cgi-bin/mailman/options/ruby-talk> --===============1662620425==--