FS#72728 - [redmine] [Security] information disclosure (CVE-2021-42326)
Attached to Project:
Community Packages
Opened by loqs (loqs) - Friday, 12 November 2021, 21:51 GMT
Last edited by Sergej Pupykin (sergej) - Saturday, 13 November 2021, 20:12 GMT
Opened by loqs (loqs) - Friday, 12 November 2021, 21:51 GMT
Last edited by Sergej Pupykin (sergej) - Saturday, 13 November 2021, 20:12 GMT
|
Details
Summary
======= The package redmine is vulnerable to information disclosure via CVE-2021-42326. Guidance ======== CVE-2021-42326 is fixed in 4.2.3. Switch to ruby2.7 now redmine supports it [1]. ruby2.6 can then be dropped as redmine is the last package using it. Change arch to x86_64 as package ships .so files. Force all ruby extensions to be built locally to pick up local flags and link to packaged libraries. Added sqlite3 to Gemfile.local to match optdepends. Remove gems from Gemfile.local that no longer appear to be needed. Remove extension related build files mkmf.log,gem_make.out and */ext/ PKGBUILD.diff [2] contains the above changes. References ========== https://security.archlinux.org/AVG-2462 https://www.redmine.org/projects/redmine/wiki/Security_Advisories https://www.redmine.org/issues/35789 https://github.com/redmine/redmine/commit/3fd9787e43f7092490e7f0ce36900bbeafd4921b [1] https://www.redmine.org/issues/31500 [2] PKGBUILD.diff |
This task depends upon
Closed by Sergej Pupykin (sergej)
Saturday, 13 November 2021, 20:12 GMT
Reason for closing: Fixed
Additional comments about closing: updated, thank you
Saturday, 13 November 2021, 20:12 GMT
Reason for closing: Fixed
Additional comments about closing: updated, thank you