Skip site navigation (1)Skip section navigation (2)
Date:      Sat, 21 Feb 2015 06:25:27 +0000
From:      bugzilla-noreply@freebsd.org
To:        ruby@FreeBSD.org
Subject:   maintainer-feedback requested: [Bug 197875] [PATCH] lang/ruby22: fix false-positive vulnerabilities when set as default ruby version.
Message-ID:  <bug-197875-21402-MsoEs2rWCY@https.bugs.freebsd.org/bugzilla/>
In-Reply-To: <bug-197875-21402@https.bugs.freebsd.org/bugzilla/>
References:  <bug-197875-21402@https.bugs.freebsd.org/bugzilla/>

next in thread | previous in thread | raw e-mail | index | archive | help
Yasuhiro KIMURA <freebsd.org@pob01.utahime.jp> has reassigned Bugzilla
Automation <bugzilla@FreeBSD.org>'s request for maintainer-feedback to
ruby@FreeBSD.org:
Bug 197875: [PATCH] lang/ruby22: fix false-positive vulnerabilities when se=
t as
default ruby version.
https://bugs.freebsd.org/bugzilla/show_bug.cgi?id=3D197875



--- Description ---
When set as default ruby version, lang/ruby22 fails to build because of
false-positive vulnerabilities as following:

root@rolling-vm-freebsd1:/ # grep DEFAULT_VERSIONS /etc/make.conf
DEFAULT_VERSIONS=3D	apache=3D2.4 perl5=3D5.20 php=3D5.5 ruby=3D2.2
root@rolling-vm-freebsd1:/ # cd /usr/ports/lang/ruby22/
root@rolling-vm-freebsd1:/usr/ports/lang/ruby22 # make
=3D=3D=3D>  ruby-2.2.0 has known vulnerabilities:
ruby-2.2.0 is vulnerable:
ruby -- multiple vulnerabilities
CVE: CVE-2006-3694
WWW: http://vuxml.FreeBSD.org/freebsd/76562594-1f19-11db-b7d4-0008743bf21a.=
html

ruby-2.2.0 is vulnerable:
Multiple implementations -- DoS via hash algorithm collision
CVE: CVE-2011-5037
CVE: CVE-2011-5036
CVE: CVE-2011-4815
CVE: CVE-2011-4838
WWW: http://vuxml.FreeBSD.org/freebsd/91be81e7-3fea-11e1-afc7-2c4138874f7d.=
html

1 problem(s) in the installed packages found.
=3D> Please update your ports tree and try again.
=3D> Note: Vulnerable ports are marked as such even if there is no update
available.
=3D> If you wish to ignore this vulnerability rebuild with 'make
DISABLE_VULNERABILITIES=3Dyes'
*** Error code 1

Stop.
make[1]: stopped in /am/eastasia/usr0/freebsd/ports/ports/lang/ruby22
*** Error code 1

Stop.
make: stopped in /am/eastasia/usr0/freebsd/ports/ports/lang/ruby22
root@rolling-vm-freebsd1:/usr/ports/lang/ruby22 #

Attached patch fixes the issue.

--- Comment #1 from Bugzilla Automation <bugzilla@FreeBSD.org> ---
Auto-assigned to maintainer ruby@FreeBSD.org=



Want to link to this message? Use this URL: <https://mail-archive.FreeBSD.org/cgi/mid.cgi?bug-197875-21402-MsoEs2rWCY>