From nobody Thu Mar 30 21:28:19 2023 X-Original-To: dev-commits-ports-all@mlmmj.nyi.freebsd.org Received: from mx1.freebsd.org (mx1.freebsd.org [IPv6:2610:1c1:1:606c::19:1]) by mlmmj.nyi.freebsd.org (Postfix) with ESMTP id 4Pnc3R3mQ8z42MXn; Thu, 30 Mar 2023 21:28:19 +0000 (UTC) (envelope-from git@FreeBSD.org) Received: from mxrelay.nyi.freebsd.org (mxrelay.nyi.freebsd.org [IPv6:2610:1c1:1:606c::19:3]) (using TLSv1.3 with cipher TLS_AES_256_GCM_SHA384 (256/256 bits) key-exchange X25519 server-signature RSA-PSS (4096 bits) server-digest SHA256 client-signature RSA-PSS (4096 bits) client-digest SHA256) (Client CN "mxrelay.nyi.freebsd.org", Issuer "R3" (verified OK)) by mx1.freebsd.org (Postfix) with ESMTPS id 4Pnc3R3L0sz3vMp; Thu, 30 Mar 2023 21:28:19 +0000 (UTC) (envelope-from git@FreeBSD.org) DKIM-Signature: v=1; a=rsa-sha256; c=relaxed/relaxed; d=freebsd.org; s=dkim; t=1680211699; h=from:from:reply-to:subject:subject:date:date:message-id:message-id: to:to:cc:mime-version:mime-version:content-type:content-type: content-transfer-encoding:content-transfer-encoding; bh=2qqA/uhgRbHsZaGcHcoWBKTyW1EjW2J9Zg9B8g3aAZg=; b=PrxYanlT0k1wJQJf1A+Fzs7aqVVyPRTkAK5ryBBHfJLglF7rKonwc/zxPF7woUlPwrJKgj R1zKKcGyvQU6P+AFMxGa1MEULk3ICDFvFPbrcpiV3LVUiJF3JDkbAjOb2zmfAcpr2kMKcx pE40IS8htpg6idDLFOMVf+ZyMnp8iZc06iUo3IrqHfhkDFAeVezxZPk22sX/vIZGls0OH2 /OejiGcKWV9KZGcvlOpoSVtWhmzi6sLv6jaDBkHlNwOrSzeO+/ljNvsc00yaA2RA+CapA3 EXDYg2rUf+0c8GbvQBiUnH0o2srcI4G5lg+MbmbXRaczYd9uQV9QWmtzYYXLYw== ARC-Message-Signature: i=1; a=rsa-sha256; c=relaxed/relaxed; d=freebsd.org; s=dkim; t=1680211699; h=from:from:reply-to:subject:subject:date:date:message-id:message-id: to:to:cc:mime-version:mime-version:content-type:content-type: content-transfer-encoding:content-transfer-encoding; bh=2qqA/uhgRbHsZaGcHcoWBKTyW1EjW2J9Zg9B8g3aAZg=; b=xkOX9Cxc1UJr/JaI5CpQL8KnWQiuu9TyWtMEasUvqXtbt+jp5HL1Xe5DcfYaeLxfxtg5q6 VFWf2jwOrxk6D07IThh5JKO5h8yclP6tShn0cWCJzAAAt7j0mKtcG5afZAmIU2qY4HkdAT 1zaHfFOqu8vh95tRY4iFzPl+HSviVJgax3DDy4omN6CLtAAHF7IVsiH2JM9FCOLvAbl00u P1JHyBG0WLLN0x95KPRTmStyujGaz87uaQ8COSZsMJ8qj71kM3HfLtxB4Vbj+1J3Rv2CGE N2XqkadMDmHmIa5i6i53VRU5PK9KZa1pzQ36jMK6OEZu7xrkgjiexIvXnKmNIQ== ARC-Authentication-Results: i=1; mx1.freebsd.org; none ARC-Seal: i=1; s=dkim; d=freebsd.org; t=1680211699; a=rsa-sha256; cv=none; b=MYEmRNh5POi6PWWzlBdcnTLjIwhVUZNLxXZEDx3GAdqrxGgYwoI0WB+PnLr/Hf6oPYuu2Y i7wGbO6evwWT5xJK+kyHpJalMxjCjbtt/4sKV/zuQMF7SnVILN0oT6Rb7pOLsMJbpvrJBh MYTbj33/qK/3qtHQv4T/R+W3yzeMXh/pJqs3PBUmNkFD4JXDTXiBy0ZQjsjTcUnZCqu1Nv wd3hIq5UdAMJlDW2HM/78Byx6ddVnZV1fdzW/j0BJ9dE/9QanTUViQpNPwEmFcrp+1dsHm 4v5jztwVcT1/ESB89v6mczpGNkNQ+VZAl0g2e2PS15+hfy3ilhO591NB7gShqA== Received: from gitrepo.freebsd.org (gitrepo.freebsd.org [IPv6:2610:1c1:1:6068::e6a:5]) (using TLSv1.3 with cipher TLS_AES_256_GCM_SHA384 (256/256 bits) key-exchange X25519 server-signature RSA-PSS (4096 bits) server-digest SHA256) (Client did not present a certificate) by mxrelay.nyi.freebsd.org (Postfix) with ESMTPS id 4Pnc3R23kxzRjH; Thu, 30 Mar 2023 21:28:19 +0000 (UTC) (envelope-from git@FreeBSD.org) Received: from gitrepo.freebsd.org ([127.0.1.44]) by gitrepo.freebsd.org (8.16.1/8.16.1) with ESMTP id 32ULSJbD053369; Thu, 30 Mar 2023 21:28:19 GMT (envelope-from git@gitrepo.freebsd.org) Received: (from git@localhost) by gitrepo.freebsd.org (8.16.1/8.16.1/Submit) id 32ULSJha053368; Thu, 30 Mar 2023 21:28:19 GMT (envelope-from git) Date: Thu, 30 Mar 2023 21:28:19 GMT Message-Id: <202303302128.32ULSJha053368@gitrepo.freebsd.org> To: ports-committers@FreeBSD.org, dev-commits-ports-all@FreeBSD.org, dev-commits-ports-main@FreeBSD.org From: Yasuhiro Kimura Subject: git: 52306be29734 - main - security/vuxml: Document ReDoS vulnerability in rubygem-time List-Id: Commit messages for all branches of the ports repository List-Archive: https://lists.freebsd.org/archives/dev-commits-ports-all List-Help: List-Post: List-Subscribe: List-Unsubscribe: Sender: owner-dev-commits-ports-all@freebsd.org X-BeenThere: dev-commits-ports-all@freebsd.org MIME-Version: 1.0 Content-Type: text/plain; charset=utf-8 Content-Transfer-Encoding: 8bit X-Git-Committer: yasu X-Git-Repository: ports X-Git-Refname: refs/heads/main X-Git-Reftype: branch X-Git-Commit: 52306be2973467a9d46978ae902529e13e1f49f7 Auto-Submitted: auto-generated X-ThisMailContainsUnwantedMimeParts: N The branch main has been updated by yasu: URL: https://cgit.FreeBSD.org/ports/commit/?id=52306be2973467a9d46978ae902529e13e1f49f7 commit 52306be2973467a9d46978ae902529e13e1f49f7 Author: Yasuhiro Kimura AuthorDate: 2023-03-30 16:53:02 +0000 Commit: Yasuhiro Kimura CommitDate: 2023-03-30 21:27:40 +0000 security/vuxml: Document ReDoS vulnerability in rubygem-time --- security/vuxml/vuln/2023.xml | 53 ++++++++++++++++++++++++++++++++++++++++++++ 1 file changed, 53 insertions(+) diff --git a/security/vuxml/vuln/2023.xml b/security/vuxml/vuln/2023.xml index 9e0b414465ca..7603d7d53531 100644 --- a/security/vuxml/vuln/2023.xml +++ b/security/vuxml/vuln/2023.xml @@ -1,3 +1,56 @@ + + rubygem-time -- ReDoS vulnerability + + + ruby + 2.7.0,12.7.8,1 + 3.0.0,13.0.6,1 + 3.1.0,13.1.4,1 + 3.2.0.p1,13.2.2,1 + + + ruby27 + 2.7.0,12.7.8,1 + + + ruby30 + 3.0.0,13.0.6,1 + + + ruby31 + 3.1.0,13.1.4,1 + + + ruby32 + 3.2.0.p1,13.2.2,1 + + + rubygem-time + 0.2.2 + + + + +

ooooooo_q reports:

+
+

+ The Time parser mishandles invalid strings that have + specific characters. It causes an increase in execution + time for parsing strings to Time objects. +

+
+ +
+ + CVE-2023-28756 + https://www.ruby-lang.org/en/news/2023/03/30/redos-in-time-cve-2023-28756/ + + + 2023-03-30 + 2023-03-30 + +
+ rubygem-uri -- ReDoS vulnerability