Skip to content

taint flag#5411

Merged
kares merged 1 commit intojruby:masterfrom
ahorek:taint
Nov 3, 2018
Merged

taint flag#5411
kares merged 1 commit intojruby:masterfrom
ahorek:taint

Conversation

@ahorek
Copy link
Contributor

@ahorek ahorek commented Nov 3, 2018

https://www.ruby-lang.org/en/news/2018/10/17/not-propagated-taint-flag-in-some-formats-of-pack-cve-2018-16396/

Array#pack('M')
Array#pack('m')
Array#pack('u')

returns a tainted string when a pack argument is tainted

Array#pack('p')
Array#pack('P')

not implemented on jruby

@kares kares merged commit 15bb169 into jruby:master Nov 3, 2018
@kares kares added this to the JRuby 9.2.1.0 milestone Nov 3, 2018
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

2 participants