Skip to content
New issue

Have a question about this project? Sign up for a free GitHub account to open an issue and contact its maintainers and the community.

By clicking “Sign up for GitHub”, you agree to our terms of service and privacy statement. We’ll occasionally send you account related emails.

Already on GitHub? Sign in to your account

CVE-2024-39908 and CVE-2024-41123 commit #232

Closed
bastien-roucaries opened this issue Jan 11, 2025 · 3 comments
Closed

CVE-2024-39908 and CVE-2024-41123 commit #232

bastien-roucaries opened this issue Jan 11, 2025 · 3 comments

Comments

@bastien-roucaries
Copy link

Hi,

On debian security side we need a statement about commit for this two CVEs

What are the commit fixing this ?

Thanks

Bastien

@kou
Copy link
Member

kou commented Jan 11, 2025

@bastien-roucaries
Copy link
Author

@kou are you sure that

CVE-2024-39908 : When it parses an XML that has many specific characters such as <, 0 and %>. REXML gem may take long time.
CVE-2024-41123: When parsing an XML document that has many specific characters such as whitespace character, >] and ]>, REXML gem may take long time.

Are fixed by a namespace fix ?

@kou
Copy link
Member

kou commented Jan 11, 2025

Ah, you referred different CVEs. Sorry.

GHSA-4xqq-m2hx-25v8 :

GHSA-r55c-59qm-vjw6 :

FYI: They may depend on other commits. So it may be difficult to backport only them. Updating to 3.3.2 or 3.3.3 will be safe. (It doesn't introduce unrelated DoS/bug by wrong backport.)

Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment
Labels
None yet
Development

No branches or pull requests

2 participants