[#30589] [Bug #3391] Use single exclamation mark instead of double exclamation mark for IRB — Diego Viola <redmine@...>

Bug #3391: Use single exclamation mark instead of double exclamation mark for IRB

10 messages 2010/06/04

[#30672] [Bug #3411] Time.local 1916,5,1 #=> 1916-04-30 23:00:00 +0100 — Benoit Daloze <redmine@...>

Bug #3411: Time.local 1916,5,1 #=> 1916-04-30 23:00:00 +0100

12 messages 2010/06/08

[#30699] [Bug #3419] 1.9.2-preview3 possible bug with Rails 3 active_record sqlite_adapter — Joe Sak <redmine@...>

Bug #3419: 1.9.2-preview3 possible bug with Rails 3 active_record sqlite_adapter

9 messages 2010/06/09

[#30734] [Bug #3428] ri outputs ansi escape sequences even when stdout is not a tty — caleb clausen <redmine@...>

Bug #3428: ri outputs ansi escape sequences even when stdout is not a tty

11 messages 2010/06/11

[#30756] [Feature #3436] Spawn the timer thread lazily — Maximilian Gass <redmine@...>

Feature #3436: Spawn the timer thread lazily

15 messages 2010/06/13
[#32686] [Ruby 1.9-Feature#3436] Spawn the timer thread lazily — Mark Somerville <redmine@...> 2010/10/04

Issue #3436 has been updated by Mark Somerville.

[ruby-core:30618] [Bug #1800][Assigned] rubygems can replace system executable files

From: Yusuke Endoh <redmine@...>
Date: 2010-06-06 13:07:13 UTC
List: ruby-core #30618
Issue #1800 has been updated by Yusuke Endoh.

Status changed from Open to Assigned
Priority changed from Urgent to Normal
Target version changed from 1.9.2 to 1.9.x

Hi,

I realized more serious concern; "sudo gem install" executes
extconf.rb with root access, which enables code execution by
"an attacker".

I think this does not means any security issue, but means a
simple fact that rubygems assumes a user does not install
untrusted gems.

It is better to have an option to prompt before rewriting a
file or executing extconf.rb.
So I move this ticket to 1.9.x feature.

-- 
Yusuke Endoh <mame@tsg.ne.jp>
----------------------------------------
http://redmine.ruby-lang.org/issues/show/1800

----------------------------------------
http://redmine.ruby-lang.org

In This Thread