Follow @Openwall on Twitter for new release announcements and other news
[<prev] [next>] [<thread-prev] [thread-next>] [day] [month] [year] [list]
Message-ID: <20140716170438.2d1a1bce@redhat.com>
Date: Wed, 16 Jul 2014 17:04:38 +0200
From: Tomas Hoger <thoger@...hat.com>
To: cve-assign@...re.org
Cc: rdecvalle@...are.com, oss-security@...ts.openwall.com, mmcallis@...hat.com
Subject: Re: Re: [ruby-core:63604] [ruby-trunk - Bug #10019]
 [Open] segmentation fault/buffer overrun in pack.c (encodes)

On Wed, 16 Jul 2014 02:04:37 -0400 (EDT) cve-assign@...re.org wrote:

> > Ruby 1.9.3, 2.0, and 2.1 are affected by the off-by-one. We're still
> > not sure about the presence of a different issue affecting Ruby 2.0
> > and 2.1. I left a comment on the report pointing out that 1.9.3 is
> > also affected by the off-by-one
> 
> Yesterday,
> 
> https://bugs.ruby-lang.org/projects/ruby-trunk/repository/revisions/46778
> 
> and
> 
> https://bugs.ruby-lang.org/projects/ruby-trunk/repository/revisions/46778/diff/pack.c
> 
> were publicly readable, but today both of them result in a "Ruby Issue
> Tracking System" login screen. We're not sure how to interpret this,
> e.g., maybe all of 46778 has become private because the "different
> issue affecting Ruby 2.0 and 2.1" is now embargoed?

That's probably unrelated change / regression in the Ruby bug tracker.

Checking some other random bug report, when logged in using a
completely unprivileged account, I see:
- revision strings (rXXXX) are clickable links pointing to URLs as above
- actual revisions / diff are accessible

While doing the same while not logged in:
- revision strings (rXXXX) are not turned to links
- revision / diff pages redirect to login

Anyway, you can view the above commit / diff via:
http://svn.ruby-lang.org/cgi-bin/viewvc.cgi?view=revision&revision=46778

-- 
Tomas Hoger / Red Hat Security Response Team

Powered by blists - more mailing lists

Please check out the Open Source Software Security Wiki, which is counterpart to this mailing list.

Confused about mailing lists and their use? Read about mailing lists on Wikipedia and check out these guidelines on proper formatting of your messages.