[DRE-maint] Bug#870852: rubocop: CVE-2017-8418

Salvatore Bonaccorso carnil at debian.org
Sat Aug 5 19:36:20 UTC 2017


Source: rubocop
Version: 0.48.1+dfsg-1
Severity: grave
Tags: patch security upstream
Forwarded: https://github.com/bbatsov/rubocop/issues/4336

Hi,

the following vulnerability was published for rubocop.

CVE-2017-8418[0]:
| RuboCop 0.48.1 and earlier does not use /tmp in safe way, allowing
| local users to exploit this to tamper with cache files belonging to
| other users.

If you fix the vulnerability please also make sure to include the
CVE (Common Vulnerabilities & Exposures) id in your changelog entry.

For further information see:

[0] https://security-tracker.debian.org/tracker/CVE-2017-8418
    https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2017-8418
[1] https://github.com/bbatsov/rubocop/issues/4336

Regards,
Salvatore



More information about the Pkg-ruby-extras-maintainers mailing list