Bug#913093: ruby-i18n: CVE-2014-10077

2018-11-20 Thread Chris Lamb
block 913093 by 914187
thanks

Hi Moritz,

> This doesn't warrant a DSA, feel free to fix it via a point
> update, though!

Thanks, filed as #914187.


Best wishes,

-- 
  ,''`.
 : :'  : Chris Lamb
 `. `'`  la...@debian.org / chris-lamb.co.uk
   `-



Bug#913093: ruby-i18n: CVE-2014-10077

2018-11-19 Thread Moritz Muehlenhoff
On Mon, Nov 19, 2018 at 03:17:48AM -0500, Chris Lamb wrote:
> Chris Lamb wrote:
> 
> > Security team, I would be more than happy to prepare and upload a
> > stable security upload of this package when addressing it in jessie
> > LTS. Please let me know and I will come back with a debdiff.
> > 
> > Ruby team, I could easily upload to sid at the same time. Let me
> > know too. (I believe I have the requisite powers in Salsa already.)
> 
> Gentle ping on the above two queries? :)

This doesn't warrant a DSA, feel free to fix it via a point update, though!

Cheers,
Moritz



Bug#913093: ruby-i18n: CVE-2014-10077

2018-11-19 Thread Chris Lamb
Chris Lamb wrote:

> Security team, I would be more than happy to prepare and upload a
> stable security upload of this package when addressing it in jessie
> LTS. Please let me know and I will come back with a debdiff.
> 
> Ruby team, I could easily upload to sid at the same time. Let me
> know too. (I believe I have the requisite powers in Salsa already.)

Gentle ping on the above two queries? :)


Regards,

-- 
  ,''`.
 : :'  : Chris Lamb
 `. `'`  la...@debian.org / chris-lamb.co.uk
   `-



Bug#913093: ruby-i18n: CVE-2014-10077

2018-11-16 Thread Chris Lamb
Hi Salvatore et al.,

> Source: ruby-i18n
[…]
> CVE-2014-10077[0]:
> | Hash#slice in lib/i18n/core_ext/hash.rb in the i18n gem before 0.8.0
> | for Ruby allows remote attackers to cause a denial of service
> | (application crash) via a call in a situation where :some_key is
> | present in keep_keys but not present in the hash.

Security team, I would be more than happy to prepare and upload a
stable security upload of this package when addressing it in jessie
LTS. Please let me know and I will come back with a debdiff.

Ruby team, I could easily upload to sid at the same time. Let me
know too. (I believe I have the requisite powers in Salsa already.)


Best wishes,

-- 
  ,''`.
 : :'  : Chris Lamb
 `. `'`  la...@debian.org / chris-lamb.co.uk
   `-



Bug#913093: ruby-i18n: CVE-2014-10077

2018-11-06 Thread Salvatore Bonaccorso
Source: ruby-i18n
Version: 0.7.0-2
Severity: important
Tags: security upstream
Forwarded: https://github.com/svenfuchs/i18n/pull/289

Hi,

The following vulnerability was published for ruby-i18n.

CVE-2014-10077[0]:
| Hash#slice in lib/i18n/core_ext/hash.rb in the i18n gem before 0.8.0
| for Ruby allows remote attackers to cause a denial of service
| (application crash) via a call in a situation where :some_key is
| present in keep_keys but not present in the hash.

If you fix the vulnerability please also make sure to include the
CVE (Common Vulnerabilities & Exposures) id in your changelog entry.

For further information see:

[0] https://security-tracker.debian.org/tracker/CVE-2014-10077
https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2014-10077
[1] https://github.com/svenfuchs/i18n/pull/289

Regards,
Salvatore