From owner-freebsd-ruby@FreeBSD.ORG Sat Feb 21 06:25:27 2015 Return-Path: Delivered-To: ruby@FreeBSD.org Received: from mx1.freebsd.org (mx1.freebsd.org [IPv6:2001:1900:2254:206a::19:1]) (using TLSv1.2 with cipher AECDH-AES256-SHA (256/256 bits)) (No client certificate requested) by hub.freebsd.org (Postfix) with ESMTPS id 83BDE4FD for ; Sat, 21 Feb 2015 06:25:27 +0000 (UTC) Received: from kenobi.freebsd.org (kenobi.freebsd.org [IPv6:2001:1900:2254:206a::16:76]) (using TLSv1.2 with cipher ECDHE-RSA-AES256-GCM-SHA384 (256/256 bits)) (Client did not present a certificate) by mx1.freebsd.org (Postfix) with ESMTPS id 6E4AD9D2 for ; Sat, 21 Feb 2015 06:25:27 +0000 (UTC) Received: from bugs.freebsd.org ([127.0.1.118]) by kenobi.freebsd.org (8.14.9/8.14.9) with ESMTP id t1L6PR3K050284 for ; Sat, 21 Feb 2015 06:25:27 GMT (envelope-from bugzilla-noreply@freebsd.org) From: bugzilla-noreply@freebsd.org To: ruby@FreeBSD.org Subject: maintainer-feedback requested: [Bug 197875] [PATCH] lang/ruby22: fix false-positive vulnerabilities when set as default ruby version. Date: Sat, 21 Feb 2015 06:25:27 +0000 X-Bugzilla-Type: request Message-ID: In-Reply-To: References: X-Bugzilla-URL: https://bugs.freebsd.org/bugzilla/ Auto-Submitted: auto-generated MIME-Version: 1.0 Content-Type: text/plain; charset="UTF-8" Content-Transfer-Encoding: quoted-printable X-BeenThere: freebsd-ruby@freebsd.org X-Mailman-Version: 2.1.18-1 Precedence: list List-Id: FreeBSD-specific Ruby discussions List-Unsubscribe: , List-Archive: List-Post: List-Help: List-Subscribe: , X-List-Received-Date: Sat, 21 Feb 2015 06:25:27 -0000 Yasuhiro KIMURA has reassigned Bugzilla Automation 's request for maintainer-feedback to ruby@FreeBSD.org: Bug 197875: [PATCH] lang/ruby22: fix false-positive vulnerabilities when se= t as default ruby version. https://bugs.freebsd.org/bugzilla/show_bug.cgi?id=3D197875 --- Description --- When set as default ruby version, lang/ruby22 fails to build because of false-positive vulnerabilities as following: root@rolling-vm-freebsd1:/ # grep DEFAULT_VERSIONS /etc/make.conf DEFAULT_VERSIONS=3D apache=3D2.4 perl5=3D5.20 php=3D5.5 ruby=3D2.2 root@rolling-vm-freebsd1:/ # cd /usr/ports/lang/ruby22/ root@rolling-vm-freebsd1:/usr/ports/lang/ruby22 # make =3D=3D=3D> ruby-2.2.0 has known vulnerabilities: ruby-2.2.0 is vulnerable: ruby -- multiple vulnerabilities CVE: CVE-2006-3694 WWW: http://vuxml.FreeBSD.org/freebsd/76562594-1f19-11db-b7d4-0008743bf21a.= html ruby-2.2.0 is vulnerable: Multiple implementations -- DoS via hash algorithm collision CVE: CVE-2011-5037 CVE: CVE-2011-5036 CVE: CVE-2011-4815 CVE: CVE-2011-4838 WWW: http://vuxml.FreeBSD.org/freebsd/91be81e7-3fea-11e1-afc7-2c4138874f7d.= html 1 problem(s) in the installed packages found. =3D> Please update your ports tree and try again. =3D> Note: Vulnerable ports are marked as such even if there is no update available. =3D> If you wish to ignore this vulnerability rebuild with 'make DISABLE_VULNERABILITIES=3Dyes' *** Error code 1 Stop. make[1]: stopped in /am/eastasia/usr0/freebsd/ports/ports/lang/ruby22 *** Error code 1 Stop. make: stopped in /am/eastasia/usr0/freebsd/ports/ports/lang/ruby22 root@rolling-vm-freebsd1:/usr/ports/lang/ruby22 # Attached patch fixes the issue. --- Comment #1 from Bugzilla Automation --- Auto-assigned to maintainer ruby@FreeBSD.org=