ruby
per5, php, pythonãªããã§ã¯ä»¥åããã²ã¨ã¤ã®Portfileã§è¤æ°ã®ã¤ã³ã¿ããªã¿ã®ãã¼ã¸ã§ã³ã«å¯¾å¿ããsubportãã¾ã¨ãã¦ç»é²ã§ããããã«ãªã£ã¦ããããã¨ãã°ãperl5ã ã¨perl5.brahcnesã»pythonã ã¨python.versionsã¨ãããªãã·ã§ã³ã§ç»é²ããsubportã®ãã¼ã¸â¦
ä¾ã«ãã£ã¦ã¯ãªã¹ãã¹ã«æ°ãããã¼ã¸ã§ã³ããªãªã¼ã¹ããã¦ããã®ã§å¯¾å¿ãã¾ãããå¤æ´ç¹ãªã©ã¯å ¬å¼ã®ãªãªã¼ã¹ã¢ãã¦ã³ã¹ãè¦ã¦ãã ãããå¾æ¥éããMacPortsç㯠ruby2.4, rake2.4, gem2.4ãªã©ãã¼ã¸ã§ã³ã®suffixãã¤ã port select --set ruby ruby24ãªã©seâ¦
ä¾ã«ãã£ã¦ã¯ãªã¹ãã¹ã«æ°ãããã¼ã¸ã§ã³ããªãªã¼ã¹ããã¦ããã®ã§å¯¾å¿ãã¾ãããå¾æ¥éããMacPortsç㯠ruby2.3, rake2.3, gem2.3ãªã©ãã¼ã¸ã§ã³ã®suffixãã¤ã port select ruby ruby23ãªã©selectã使ãã¨ãsuffixãªãã®ãã¼ã¸ã§ã³ã§ä½¿ãã ã¨ãªã£ã¦ãã¾â¦
ããããããã¼ã¸ã§ã³ããªãªã¼ã¹ããã¦ããã®ã§å¯¾å¿ãã¾ãããä»åã®ãã¼ã¸ã§ã³ã¯ã»ãã¥ãªãã£ä¿®æ£ï¼CVE-2015-7551: Fiddle 㨠DL ã«ããã tainted æåå使ç¨æã®èå¼±æ§ã«ã¤ãã¦ï¼ãå«ã¾ãã¦ãã¾ãã port:ruby22: 2.2.4 port:ruby21: 2.1.8 port:ruby20: â¦
ããããããã¼ã¸ã§ã³ããªãªã¼ã¹ããã¦ããã®ã§å¯¾å¿ãã¾ããã port:ruby22: 2.2.3 port:ruby21: 2.1.7 port:ruby20: 2.0.0-p647 RubyGemsã®CVE-2015-3900ã®ã»ãã¥ãªãã£ä¿®æ£ãå«ã¾ãã¦ãããã¾ãã詳ããã¯å ¬å¼ã®ãªãªã¼ã¹ã¢ãã¦ã³ã¹ãã¿ã¦ãã ãããã¾ããâ¦
ããããããã¼ã¸ã§ã³ããªãªã¼ã¹ããã¦ããã®ã§å¯¾å¿ãã¾ããã port:ruby22: 2.2.2 port:ruby21: 2.1.6 port:ruby20: 2.0.0-p645 2.2ã«ã¯tk-8.6対å¿ãå ¥ã£ãã¿ãããªãã ãã©ãæå ã§ã®ç¢ºèªãçµãããªãã£ãã®ã§tkããªã¢ã³ãã¯ã¾ã æå¹ã«ãã¦ãã¾ããã次ã¾â¦
ããããããã¼ã¸ã§ã³ããªãªã¼ã¹ããã¦ããã®ã§å¯¾å¿ãã¾ããã port:ruby22: 2.2.1 port:ruby20: 2.0.0-p643 2.0.0ã¯æå¾ã®é常ãªãªã¼ã¹ã§ãã2.2.1ã¯ãã¶ãé常ã®å®æãªãªã¼ã¹ã ã¨æãã¾ããã¾ãã1.9.3ç³»ã¯å æã§ãµãã¼ãçµäºãã¾ãããä»ã¾ã§ãããã¨ãï¼
ãã¾ããã2.2.0ã§ããåºæ¬çã«ä»ã¾ã§ã¨åãã§ãã ruby2.2, rake2.2, gem2.2ãªã©ãã¼ã¸ã§ã³ã®suffixãã¤ã port select ruby ruby22ãªã©selectã使ãã¨ãsuffixãªãã®ãã¼ã¸ã§ã³ã§ä½¿ãã
ããããããã¼ã¸ã§ã³ããªãªã¼ã¹ããã¦ããã®ã§å¯¾å¿ãã¾ããã port:ruby21: 2.1.5 port:ruby20: 2.0.0-p598 port:ruby19: 1.9.4-p551 ä»åãã»ãã¥ãªãã£ä¿®æ£ãå«ã¿ã¾ãã詳細ã¯å ¬å¼ã®æ å ±ãããããã ããã "CVE-2014-8090: REXML ã«ããã XML å±éã«ä¼´â¦
ããããããã¼ã¸ã§ã³ããªãªã¼ã¹ããã¦ããã®ã§å¯¾å¿ãã¾ããã port:ruby21: 2.1.4 port:ruby20: 2.0.0-p594 port:ruby19: 1.9.4-p550 ä»åã®ãªãªã¼ã¹ã¯ã»ãã¥ãªãã£ä¿®æ£ãå«ã¿ã¾ãã詳細ã¯å ¬å¼ã®æ å ±ãããããã ããã "CVE-2014-8080: REXML ã«ãããXMLâ¦
ã¡ãã£ã¨åã«MacPortsã®ãã±ããã§åãåããããã¦ãï¼#45257 (ruby20: warnings from library files that differ only by case of filename) â MacPortsï¼ãã®ã«ã¤ãã¦ãæ £ãã¦ãã¨ããããããã¤ããã ãã©ãæ°ä»ããªãã¨ã ãã¶ã¤ãããªã®ã§ã¡ã¢æ®ãã¨ãâ¦
ãã±ãããæ¥ã¦ãã®ã§å¯¾å¿ãã¾ãããå 容ã«ã¤ãã¦ã¯rubyã®issie#9897ã«ããã¨ããã§ãããã¡ãç°¡åã«èª¬æããã¨ããã«ãæã«ãã¯ãã¨ãã¦RUBY_LIBFFI_MODVERSIONã¨ããå¤ãå®ç¾©ãã¦ããã®ã§ãããå¾æ¥ã®"3.0.13"ã®ãããªæ°å3ã¤ã®ãã¼ã¸ã§ã³ãã"3.1"ã¨ããâ¦
ãã¾ãããå¤æ´ç¹ãªã©ã¯æ¬å®¶ã®ãªãªã¼ã¹ãè¦ã¦ãã ããã https://www.ruby-lang.org/ja/news/2014/05/09/ruby-2-1-2-is-released/ https://www.ruby-lang.org/ja/news/2014/05/09/ruby-2-0-0-p481-is-released/ MacPortsçã«ã¯ readline-6.3対å¿ããããã®ã§â¦
port:readlineã6.3ã«æ´æ°ããã¦ããã ãã©ãããã ã¨port:ruby21ã®æ¡å¼µã¢ã¸ã¥ã¼ã«ãã³ã³ãã¤ã«ã¨ã©ã¼ã«ãªãã¨ã®ãã°ã¬ãã¼ãããã¦ãã https://trac.macports.org/ticket/43296 rubyã®trunkã¯å¯¾å¿æ¸ã¿(bugs:9578)ã ã£ãã®ã§ããã£ãããããã¤ããã ãã¦reâ¦
MacPortsã®ããã±ã¼ã¸ãããããæ´æ°ãã¾ãããåãªãªã¼ã¹ã®æ´æ°å 容ãªã©ã«ã¤ãã¦ã¯å ¬å¼ã®ã¢ãã¦ã³ã¹ãåç §ãã ããã Ruby 2.1.1 ãªãªã¼ã¹ Ruby 2.0.0-p451 ãªãªã¼ã¹ Ruby 1.9.3-p545 ãªãªã¼ã¹ ã¢ãã¦ã³ã¹ã«ããããã«ã1.9.3ã¯ä»å¾1å¹´éã»ãã¥ãªãã£ã¡ã³ãâ¦
ãã¾ããã2.1.0ã§ããã¡ãã£ã¨ç¢ºèªã«æéåã£ãããªã©ãªã©ã§é ããªãã¾ããããåºæ¬çã«ä»ã¾ã§ã¨åãã§ãã ruby2.1, rake2.1, gem2.1ãªã©ãã¼ã¸ã§ã³ã®suffixãã¤ã port select ruby ruby2.1ãªã©selectã使ãã¨ãsuffixãªãã®ãã¼ã¸ã§ã³ã§ä½¿ãã ä»ã¾ã§ã¨â¦
æ°ãããã¼ã¸ã§ã³ãã§ã¦ãã®ã§MacPortsã®ã»ããæ´æ°ãã¾ãããã»ãã¥ãªãã£ä¿®æ£ãããã¾ãã æµ®åå°æ°ç¹æ°ãã¼ã¹ã«ããããã¼ããªã¼ãã¼ããã¼ (CVE-2013-4164)
ç°ä¸å²ããã®ãããã°ã©ãã³ã°è¨èªRubyã«GMPãçµã¿è¾¼ãããè¦ãªããããããã12æã«ãªãªã¼ã¹ãããã§ããã2.1ã®MacPortsã§ã®gmp対å¿ã©ãããããã¨ãèããã gmpããªã¢ã³ãã追å ããã©ã«ãç¡å¹ ãããã§ããããããããªã¢ã³ãããã®ãï¼ã¨ããæ°ãããâ¦
ruby19ã¨ruby20ã§+mactkããªã¢ã³ããæå®ããéã«ããã«ãèªä½ã¯æåãããã®ã®ãtkutil.bundleãtcltklib.bundleã¨ãã£ãæ¡å¼µã©ã¤ãã©ãªãä½æãããªãåé¡ãããã®ãä¿®æ£ãã¾ããã詳細ã¯[ruby-list:49520]ãããããã ãããã¾ãããã£ã¦ããã©ãmactk使â¦
ãã¾ãããCVE-2013-4073ãªã©ã®èå¼±æ§ä¿®æ£ãå«ã¾ãã¦ãã¾ãã http://www.ruby-lang.org/ja/news/2013/06/27/hostname-check-bypassing-vulnerability-in-openssl-client-cve-2013-4073/ ã¾ãã以åããäºåããã¦ããããã«ã6ææ«ã§1.8.7ã®ä¿å®ãçµäºãã¦â¦
ãã¾ãããCVE-2013-2065ãªã©ã®èå¼±æ§ä¿®æ£ãå«ã¾ãã¦ãã¾ãã http://www.ruby-lang.org/ja/news/2013/05/14/taint-bypass-dl-fiddle-cve-2013-2065/
MacPortsã®Wikiã«RubySectionã¨ãããã¼ã¸ããããã ãã©ãå 容ãã ãã¶å¤ãã®ã§ã©ãã«ãããããport select rubyãå°å ¥ãããã¨ãã®ã¸ãã®äºæ ãåæ ããªãã¨ãªã®ã§ããã¨ãããããã©ããã¿ãããªã®ãæ¥æ¬èªã§æ¸ãã¨ãã ã¦ã¼ã¶åã portéçºè åã ã®ä¸¡â¦
ã¡ã¾ã¡ã¾ã¨æ°ãã¤ããã¨ããç´ããããruby20ã§ã®ruby.setupã®åä½ç¢ºèªãããã port:rb-cocoa ãå£ãã¦ãã®ã§ç´ãã ruby.setup extconf.rbã§-rvendor-specific.rbã§ãªã--vendorã«ãruby20ã§ã¯ã©ããã¦ãå¿ è¦ã«ãªãã¾ã§vendor-specific.rbã¯å°å ¥ããªãäºå®â¦
selectã®æºåãã¨ã¨ã®ã£ãã®ã§ãport:ruby20ãä½æãã¦ç»é²ãããrubyãruby19ã¨åæ§ã«ã³ãã³ãã¯ruby2.0, gem2.0ãªã©ã®ãã¡ã¤ã«åã«ãªã£ã¦ãã¦ãport select rubyãå¹ãããã«ãªã£ã¦ãã 調ã¹ããã¨ã¨ã ã©ãã2.0.0ã§configureã«--with-librubyprefixãæâ¦
2chã®MacPortsã¹ã¬ã§ææããã£ã¦èª¿ã¹ã¦ã¿ããããããã«+tkãªã®ã«Tk.frameworkã«ãªã³ã¯ãã¦ããext/tkã®extconf.rbè¦ãããããæ示çã«--disable-tcltk-frameworkããªãã¨Macã§ã¯Tk.frameworkãé¸ã¶ããã«ãªã£ã¦ããããã ãã§ãtkããªã¢ã³ãã«configure.aâ¦
ãã¾ãããCVE-2013-0269ãªã©ã®èå¼±æ§ä¿®æ£ãå«ã¾ãã¦ãã¾ãã http://www.ruby-lang.org/ja/news/2013/02/22/ruby-1-9-3-p392-is-released/ ã¾ããXcode-4.6ã§ã³ã³ãã¤ã«ã§ããªãã¨ãã話é¡ãããã£ã¦ãã¾ããããã±ããã«è¨è¼ã®ããããMacPortsã§ãå½ã¦ãâ¦
ãã¾ãããCVE-2013-0256ã®èå¼±æ§ä¿®æ£ãå«ã¾ãã¦ãã¾ãã http://www.ruby-lang.org/ja/news/2013/02/06/rdoc-xss-cve-2013-0256/
ãªãªã¼ã¹ããã¦ãã®ã§æ´æ°ãã¾ãããp362ã使ç¨æã«Railsã§SEGVãããã¨ã®ããåé¡ãä¿®æ£ããã¦ããããã§ãã http://www.ruby-lang.org/ja/news/2013/01/17/ruby-1-9-3-p374-is-released/ Mountain Lionã¨Lionã§make test-allãéããã¨ã確èªãã¦ãã¾ãã
MacOSX10.8(Mountain Lion)ä»å±ã®rubyã§bignum(?)ã«åé¡ã®ç¶ããé²å±ã¨ãããããªãã£ãã¨ããã¹ããããããã rdar://11806241 ãã²ãã³ãã«æ´æ°ããããã§ãããrdar://11066071 ã¨éè¤ã¨ãããã¨ã§ã¯ãã¼ãºã«ãªãã¾ããã次ã®ã¢ãããã¼ãã¨ãã§ç´ãã¨ãâ¦
ã¯ãªã¹ãã¹ã«ãªãªã¼ã¹ããã¦ãã®ã§æ´æ°ãã¾ããã http://www.ruby-lang.org/ja/news/2012/12/25/ruby-1-9-3-p362-is-released/ MacPortsçã§ã¯ãSegmentation Faultãèµ·ãããã¨ãããåé¡ã®å¯¾å¿ããããå ¥ãã¦ãã¾ãããã®ããããp363ãªã®ã§ãå®éã«ã¯p36â¦