Re: Ruby vulnerability?



On Sat, Jul 29, 2006 at 07:54:16PM +0200, Remko Lodder wrote:

Sergey Matveychuk wrote:
Shaun Amott wrote:
On Fri, Jul 28, 2006 at 03:03:43PM +1000, Joel Hatton wrote:
FYI, Red Hat released an advisory today about a vulnerability in Ruby. So
far it doesn't appear in the VuXML, but am I correct in presuming it will
soon?

I've added it; thanks for the report.


Can we get patches somewhere? I can't find any.


It is said that the patches are available through the CVSweb
but all the information I could fine was in japanese, which is
a bit difficult to read for me (read: i do not speak nor read
japanese at all).

The CVE report seemed to imply that there was a fix in 1.8.5, which I
assumed had therefore been released. But it seems this isn't the case.

The Ruby folks say they don't publish advisories until there is a fix
ready; and there is no mention of this vulnerability on the website.

--
Shaun Amott [ PGP: 0x6B387A9A ]
Scientia Est Potentia.
_______________________________________________
freebsd-security@xxxxxxxxxxx mailing list
http://lists.freebsd.org/mailman/listinfo/freebsd-security
To unsubscribe, send any mail to "freebsd-security-unsubscribe@xxxxxxxxxxx"



Relevant Pages

  • [ANNOUNCE] Stacked GIT 0.13
    ... operations are performed using GIT commands and the patches are stored ... Safety checks for the 'rebase' command ... already modified by the current patch ... Fix bash completion to not garble the screen with an error message. ...
    (Linux-Kernel)
  • 2.6.21-mm2
    ... A handful of IDE patches were dropped due to compilation failures. ... See the `hot-fixes' directory for any important updates to this patchset. ... If you hit a bug in -mm and it is not obvious which patch caused it, ... sunrpc fix ...
    (Linux-Kernel)
  • 2.6.17-mm4
    ... The RAID patches have been dropped due to testing failures in -mm3. ... The SCSI Attached Storage tree has been restored. ... See the `hot-fixes' directory for any important updates to this patchset. ... Fix reject due to git-agpgart.patch. ...
    (Linux-Kernel)
  • Re: Q824143 -- how to get patch?!?
    ... There are 2 sorts of patches. ... client or clients that are have an issue. ... They are available from product support if the engineer while working with ... the client identifies that this fix will fix the specific problem the client ...
    (microsoft.public.security)
  • Re: [BUG] sched: big numa dynamic sched domain memory corruption
    ... fix group power for allnodes_domains ... Is the first of the above three patches the one needed to fix the "big ... This patch in turn seems to have some important fixes and followups ... Which of the following would you recommend I advise SUSE do for SLES10: ...
    (Linux-Kernel)