[#29911] [Bug #3231] Digest Does Not Build — Charlie Savage <redmine@...>
Bug #3231: Digest Does Not Build
[#29920] [Feature #3232] Loops (while/until) should return last statement value if any, like if/unless — Benoit Daloze <redmine@...>
Feature #3232: Loops (while/until) should return last statement value if any, like if/unless
Hi,
On 2 May 2010 01:56, Yukihiro Matsumoto <matz@ruby-lang.org> wrote:
Hi,
On 2 May 2010 15:24:52 UTC+2, Nobuyoshi Nakada <nobu@ruby-lang.org> wrote:
[#29953] [Bug #3241] gem update --system Segmentation fault — Benedikt Eickhoff <redmine@...>
Bug #3241: gem update --system Segmentation fault
Hi,
On Mon, May 03, 2010 at 08:55:14PM +0900, Yusuke ENDOH wrote:
[#29993] [Feature:trunk] thread-local yamler — Nobuyoshi Nakada <nobu@...>
Hi,
[#29997] years in Time.utc — Xavier Noria <fxn@...>
Does anyone have a precise statement about the years supported by
On Tue, May 4, 2010 at 8:05 AM, Xavier Noria <fxn@hashref.com> wrote:
Hi,
Hi,
[#30002] 1.9.1 lib dirs? — Roger Pack <rogerdpack2@...>
Hi all.
On Tue, May 4, 2010 at 3:00 PM, Roger Pack <rogerdpack2@gmail.com> wrote:
[#30010] [Bug #3248] extension 'tk' is finding tclConfig.sh and tkConfig.sh incorrectly — Luis Lavena <redmine@...>
Bug #3248: extension 'tk' is finding tclConfig.sh and tkConfig.sh incorrectly
Issue #3248 has been updated by Luis Lavena.
[#30023] [Bug #3250] [BUG] Segmentation fault — Diogo Almeida <redmine@...>
Bug #3250: [BUG] Segmentation fault
[#30070] [Bug #3255] Trunk fail to build without explicit ./configure options (yaml.h not found) — Benoit Daloze <redmine@...>
Bug #3255: Trunk fail to build without explicit ./configure options (yaml.h not found)
Hi,
[#30094] suggestion: switch default name for BINARY encoding — Roger Pack <rogerdpack2@...>
Situation:
(2010/05/08 7:50), Roger Pack wrote:
[#30145] [Bug #3273] Float string conversion — Marc-Andre Lafortune <redmine@...>
Bug #3273: Float string conversion
[#30154] [Bug #3275] incompatibility of testrb — Yusuke Endoh <redmine@...>
Bug #3275: incompatibility of testrb
[#30175] [Problem] DATA and __END__ in a loaded rb file — Charles Cui <zheng.cuizh@...>
how to get global constant DATA in file <a.rb>,if a.rb is loaded by b.rb.
[#30182] [Bug #3281] fail to build fiddle on Debian/lenny by default — Yusuke Endoh <redmine@...>
Bug #3281: fail to build fiddle on Debian/lenny by default
2010/5/12 Yusuke Endoh <redmine@ruby-lang.org>:
On Wed, May 12, 2010 at 11:26:44PM +0900, Tanaka Akira wrote:
2010/5/14 Aaron Patterson <aaron@tenderlovemaking.com>:
[#30226] [Bug #3288] Segmentation fault - activesupport-3.0.0.beta3/lib/active_support/callbacks.rb:88 — Szymon Jeż <redmine@...>
Bug #3288: Segmentation fault - activesupport-3.0.0.beta3/lib/active_support/callbacks.rb:88
Issue #3288 has been updated by Szymon Je甜.
[#30249] [Bug #3299] revision.h rule in common.mk is broken for MSVC — Romulo Ceccon <redmine@...>
Bug #3299: revision.h rule in common.mk is broken for MSVC
[#30290] [Bug #3309] net/http calls leak memory and file handles in windows — Pete Higgins <redmine@...>
Bug #3309: net/http calls leak memory and file handles in windows
[#30315] [Bug #3320] emacs ruby-mode.el font-lock fails on symboled string ending with ? — Zev Blut <redmine@...>
Bug #3320: emacs ruby-mode.el font-lock fails on symboled string ending with ?
[#30323] [Feature #3322] Simple Patch to make ruby copy-on-write-friendly — Daniel DeLorme <redmine@...>
Feature #3322: Simple Patch to make ruby copy-on-write-friendly
[#30358] tk doesn't startup well in doze — Roger Pack <rogerdpack2@...>
Currently with 1.9.x and tk 8.5,the following occurs
From: Roger Pack <rogerdpack2@gmail.com>
> Does it occur with RubyTk-Kit version (it based on latest tcltklib.c)?
[#30401] [Bug #3336] Memory leak in IO.select() on Windows — HD Moore <redmine@...>
Bug #3336: Memory leak in IO.select() on Windows
[#30406] [Bug #3337] MS-DOS device names are identified as readable_real — HD Moore <redmine@...>
Bug #3337: MS-DOS device names are identified as readable_real
[#30434] [Feature #3346] __DIR__ revisted — Thomas Sawyer <redmine@...>
Feature #3346: __DIR__ revisted
[#30449] [Bug #3350] Protected methods & documentation — Marc-Andre Lafortune <redmine@...>
Bug #3350: Protected methods & documentation
[#30451] [Bug #3352] Delegates: protected methods — Marc-Andre Lafortune <redmine@...>
Bug #3352: Delegates: protected methods
[#30513] [Bug #3365] floats revisited (see bug 1841) — Roberto Tomás Collins McCarthy <redmine@...>
Bug #3365: floats revisited (see bug 1841)
[ruby-core:29925] [Bug #3234] YAML fails to load a dumped string (exception)
Bug #3234: YAML fails to load a dumped string (exception)
http://redmine.ruby-lang.org/issues/show/3234
Author: HD Moore
Status: Open, Priority: Normal
ruby -v: ruby 1.9.2dev (2010-04-27 trunk 27507) [x86_64-linux]
A specific (but common) sequence of bytes cannot be loaded after being dumped by YAML. This has a serious impact on AR serialization when a malicious user can input a string to be serialized. It also happens to break my app. The bug occurs on 1.8.7, 1.9.1-stable, and trunk.
<code>
require 'yaml'
str = ["0a20200a202020566f6c756d6520696e206472697665204320686173206e6f206c6162656c2e0d0a202020566f6c756d652053657269616c204e756d62657220697320414337392d393934320d0a20200d0a2020204469726563746f7279206f6620633a5c0d0a20200d0a202030372f31362f32303038202031303a333520504d202020202020202020202020202020202030204155544f455845432e4241540d0a202030332f32332f32303130202030333a303920504d20202020202020202020202033332c3935362062756c6b77686f69732e7064660d0a202030372f31362f32303038202031303a333520504d20202020202020202020202020202020203020434f4e4649472e5359530d0a202030372f31372f32303038202030383a343020414d202020203c4449523e20202020202020202020446f63756d656e747320616e642053657474696e67730d0a202030352f30312f32303130202031323a353620504d202020203c4449523e202020202020202020206d65746173706c6f69740d0a202030352f30312f32303130202031323a353120504d202020203c4449523e2020202020202020202050726f6772616d2046696c65730d0a202031322f30332f32303039202030373a303720414d202020203c4449523e2020202020202020202057494e444!
f57530d0a2020202020202020202020202020202020332046696c6528732920202020202020202033332c3935362062797465730d0a20202020202020202020202020202020203420446972287329202031352c3034352c3832342c35313220627974657320667265650d0a20200a20200a"].pack("H*")
YAML.load(YAML.dump_stream(str))
</code>
Stack trace:
' (ArgumentError)by-1.9.1-head/lib/ruby/1.9.1/syck.rb:135:in `load': syntax error on line 8, col 2: ` 07/16/2008 10:35 PM 0 AUTOEXEC.BAT
from /home/hdm/.rvm/ruby-1.9.1-head/lib/ruby/1.9.1/syck.rb:135:in `load'
from yaml_death.rb:5:in `<main>'
----------------------------------------
http://redmine.ruby-lang.org