Skip to content

CVE-2024-39908 and CVE-2024-41123 commit #232

Description

@bastien-roucaries

Hi,

On debian security side we need a statement about commit for this two CVEs

What are the commit fixing this ?

Thanks

Bastien

Activity

  1. kou commented on Jan 11, 2025

    @kou
    Member
  2. bastien-roucaries commented on Jan 11, 2025

    @bastien-roucaries
    Author

    @kou are you sure that

    CVE-2024-39908 : When it parses an XML that has many specific characters such as <, 0 and %>. REXML gem may take long time.
    CVE-2024-41123: When parsing an XML document that has many specific characters such as whitespace character, >] and ]>, REXML gem may take long time.

    Are fixed by a namespace fix ?

  3. kou commented on Jan 11, 2025

    @kou
    Member

    Ah, you referred different CVEs. Sorry.

    GHSA-4xqq-m2hx-25v8 :

    GHSA-r55c-59qm-vjw6 :

    FYI: They may depend on other commits. So it may be difficult to backport only them. Updating to 3.3.2 or 3.3.3 will be safe. (It doesn't introduce unrelated DoS/bug by wrong backport.)

Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Metadata

Metadata

Assignees

No one assigned

    Labels

    No labels
    No labels

    Type

    No type

    Projects

    No projects

      Milestone

      No milestone

      Relationships

      None yet

      Development

      No branches or pull requests

      Issue actions