ruby: remove CVE-2018-1000073.patch as already fixed

rubygems 2.7.6 which is in ruby 2.5.3 has this fix and as currently
applied all gem extraction fails as the realpath check is done against
the full path including the file to be extracted which will always fail
as the file hasnt been extracted yet

(From OE-Core rev: a9cc1b3f9a684c14f02b06226693b023adc3e609)

Signed-off-by: Brett Grandbois <brett.grandbois@opengear.com>
Signed-off-by: Richard Purdie <richard.purdie@linuxfoundation.org>
Signed-off-by: Armin Kuster <akuster808@gmail.com>
Signed-off-by: Richard Purdie <richard.purdie@linuxfoundation.org>
This commit is contained in:
Grandbois, Brett
2019-02-08 01:30:34 +00:00
committed by Richard Purdie
parent 589437ee23
commit 0e159278a1
2 changed files with 0 additions and 35 deletions

View File

@@ -1,34 +0,0 @@
From 1b931fc03b819b9a0214be3eaca844ef534175e2 Mon Sep 17 00:00:00 2001
From: Jonathan Claudius <jclaudius@mozilla.com>
Date: Wed, 7 Feb 2018 23:54:52 -0500
Subject: [PATCH] Non-working patch for deducing symlinked base-dirs
---
CVE: CVE-2018-1000073
Fixed in ruby 2.7.6.
Upstream-Status: Backport [github.com/rubygems/rubygems/commit/1b931fc...]
Signed-off-by: Joe Slater <joe.slater@windriver.com>
---
lib/rubygems/package.rb | 2 ++
1 file changed, 2 insertions(+)
diff --git a/lib/rubygems/package.rb b/lib/rubygems/package.rb
index dede959..cb9c74a 100644
--- a/lib/rubygems/package.rb
+++ b/lib/rubygems/package.rb
@@ -421,6 +421,8 @@ EOM
destination_dir = File.expand_path destination_dir
destination = File.join destination_dir, filename
+ destination = File.realpath destination if
+ File.respond_to? :realpath
destination = File.expand_path destination
raise Gem::Package::PathError.new(destination, destination_dir) unless
--
1.7.9.5

View File

@@ -3,7 +3,6 @@ require ruby.inc
SRC_URI += " \
file://ruby-CVE-2017-9226.patch \
file://ruby-CVE-2017-9228.patch \
file://CVE-2018-1000073.patch \
"
SRC_URI[md5sum] = "20c85b67846d49622ef3b24230803fef"