mruby contained a security bug that was fixed upstream

Bug #1763905 reported by Daniel
256
This bug affects 1 person
Affects Status Importance Assigned to Milestone
Ubuntu CVE Tracker
Fix Released
Undecided
Unassigned
mruby (Ubuntu)
Confirmed
Medium
Unassigned

Bug Description

A security issue within mruby has been identified and has already been fixed (see https://github.com/mruby/mruby/issues/3995).
Please assign a CVE.
Cheers, Daniel

CVE References

Revision history for this message
Steve Beattie (sbeattie) wrote :

Hi, thanks for the report. Unfortunately, as the issue is public, we can not issue a CVE for it. I have submitted a CVE request to https://cveform.mitre.org/ and will report back when MITRE has assigned a CVE for this issue.

Also, since the package referred to in this bug is in universe, it is community maintained. If you are able, I suggest coordinating with upstream and posting a debdiff for this issue. When a debdiff is available, members of the security team will review it and publish the package. See the following link for more information: https://wiki.ubuntu.com/SecurityTeam/UpdateProcedures .

Thanks!

Changed in mruby (Ubuntu):
status: New → Confirmed
importance: Undecided → Medium
information type: Private Security → Public Security
Revision history for this message
Steve Beattie (sbeattie) wrote :

This was assigned CVE-2018-10191.

Steve Beattie (sbeattie)
tags: added: community-security
Steve Beattie (sbeattie)
Changed in ubuntu-cve-tracker:
status: New → Fix Released
To post a comment you must log in.
This report contains Public Security information  
Everyone can see this security related information.

Other bug subscribers

Remote bug watches

Bug watches keep track of this bug in other bug trackers.