FazBrowse GitHub Viewer | Trending |
URL:
| Home
Tools: [Download Repo ZIP]   [Original HTTPS Page]

Update to jBCrypt 0.4 to correct an integer overflow by reedloden · Pull Request #112 · bcrypt-ruby/bcrypt-ruby · GitHub

Repository navigation

Update to jBCrypt 0.4 to correct an integer overflow - #112

Closed
reedloden wants to merge 1 commit into
bcrypt-ruby:masterfrom
reedloden:jBCrypt-0.4
Closed

reedloden wants to merge 1 commit into
bcrypt-ruby:masterfrom
reedloden:jBCrypt-0.4

Conversation

Copy link
Copy Markdown

Copy link
Copy Markdown
Author

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

Choose a reason Spam Abuse Off Topic Outdated Duplicate Resolved Low Quality

@Oscil8, does the below change end up fixing #82? Haven't had a chance to test yet, but if so, awesome...

Copy link
Copy Markdown

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

Choose a reason Spam Abuse Off Topic Outdated Duplicate Resolved Low Quality

The problem with character encoding has already failed by this point -- JRuby => Java conversion of the string has already turned out of range characters into 0xfffd (Replacement character); and the use of getBytes("UTF-8") at https://github.com/reedloden/bcrypt-ruby/blob/jBCrypt-0.4/ext/jruby/bcrypt_jruby/BCrypt.java#L676 further distorts the byte values. We've implemented a workaround here https://github.com/lookout/bcrypt-ruby/tree/lookout

Copy link
Copy Markdown
Author

The upstream issue is CVE-2015-0886 (also see http://osvdb.org/show/osvdb/119055).

tjschuck commented Jan 4, 2019

Copy link
Copy Markdown
Collaborator

As of #182, we no longer use the original jBCrypt — we now use the spring-security fork, which has since drifted away from jBCrypt 0.3 or 0.4.

tjschuck closed this Jan 4, 2019
This file contains hidden or bidirectional Unicode text that may be interpreted or compiled differently than what appears below. To review, open the file in an editor that reveals hidden Unicode characters. Learn more about bidirectional Unicode characters
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

3 participants


Back | FazBrowse Home | New Git URL