Security Vulnerability in Ruby on Rails 1.1.x




Product: Ruby on Rails
Affected: 1.1.0, 1.1.1, 1.1.2, 1.1.4, 1.1.5

Problem Description
-------------------

Scott Barron and Tobias Luetke, of the Ruby on Rails Core Team, discovered a fault with the dependency resolution mechanism which can, when exploited by a remote attacker, leave a system vulnerable to denial of service attacks, or even data loss.

All users of affected releases are advised to upgrade, or apply the relevant patches immediately.

URL: http://weblog.rubyonrails.org/2006/8/10/rails-1-1-6-backports-and-full-disclosure

Patches
-------
1.1.0: http://www.rubyonrails.org/files/aug_10_security/rel_1-1-0.diff
1.1.1: http://www.rubyonrails.org/files/aug_10_security/rel_1-1-1.diff
1.1.2: http://www.rubyonrails.org/files/aug_10_security/rel_1-1-2.diff
1.1.4: http://www.rubyonrails.org/files/aug_10_security/rel_1-1-4.diff

1.1.5 users should upgrade to 1.1.6.



Relevant Pages

  • Re: Megatouch Questions
    ... I agree I really love my Ruby 2 and I dont see any need to upgrade to ... To upgrade your machine to Crown, ... > really aren't that much better than the Ruby or Sapphire editions, ...
    (rec.games.video.arcade.collecting)
  • [ANN] RJS, Active Record++, respond_to, integration tests, and 500 other things!
    ... The biggest upgrade in Rails history has finally arrived. ... But of course we also have an impressive line of blockbuster features ... The star of our one-one show is RJS: JavaScript written in Ruby. ...
    (comp.lang.ruby)
  • Correctly upgrading ruby on MS Windows
    ... Presently I am on Ruby version 1.8.6 ... I am looking to upgrade to version 1.8.6 patch level ... When I checked the rails ...
    (comp.lang.ruby)
  • Ruby 1.8.6 Source and Apt-Get Upgrade
    ... I upgraded my packages using apt-get yesterday and have found an issue with my installed version of Ruby 1.8.6. ... RubyGems Environment is I think still showing the right info: ... Unfortunately I need to stick with RubyGems .9 and Ruby 1.8.6 for now for my current projects - so I can't just upgrade to 1.8.7. ...
    (Debian-User)
  • Re: Segfault when requiring both mysql and mechanize
    ... script worked fine in version 1.8.6 but after the upgrade generates a ... How did you upgraded your Ruby? ... AFAIK the binary version of mysql gem is *only* for 1.8, ...
    (comp.lang.ruby)

Loading