[#30589] [Bug #3391] Use single exclamation mark instead of double exclamation mark for IRB — Diego Viola <redmine@...>

Bug #3391: Use single exclamation mark instead of double exclamation mark for IRB

10 messages 2010/06/04

[#30672] [Bug #3411] Time.local 1916,5,1 #=> 1916-04-30 23:00:00 +0100 — Benoit Daloze <redmine@...>

Bug #3411: Time.local 1916,5,1 #=> 1916-04-30 23:00:00 +0100

12 messages 2010/06/08

[#30699] [Bug #3419] 1.9.2-preview3 possible bug with Rails 3 active_record sqlite_adapter — Joe Sak <redmine@...>

Bug #3419: 1.9.2-preview3 possible bug with Rails 3 active_record sqlite_adapter

9 messages 2010/06/09

[#30734] [Bug #3428] ri outputs ansi escape sequences even when stdout is not a tty — caleb clausen <redmine@...>

Bug #3428: ri outputs ansi escape sequences even when stdout is not a tty

11 messages 2010/06/11

[#30756] [Feature #3436] Spawn the timer thread lazily — Maximilian Gass <redmine@...>

Feature #3436: Spawn the timer thread lazily

15 messages 2010/06/13
[#32686] [Ruby 1.9-Feature#3436] Spawn the timer thread lazily — Mark Somerville <redmine@...> 2010/10/04

Issue #3436 has been updated by Mark Somerville.

[ruby-core:30620] Re: [Bug #1800][Assigned] rubygems can replace system executable files

From: Luis Lavena <luislavena@...>
Date: 2010-06-06 13:53:17 UTC
List: ruby-core #30620
On Sun, Jun 6, 2010 at 9:07 AM, Yusuke Endoh <redmine@ruby-lang.org> wrote:
>
> I realized more serious concern; "sudo gem install" executes
> extconf.rb with root access, which enables code execution by
> "an attacker".
>
> I think this does not means any security issue, but means a
> simple fact that rubygems assumes a user does not install
> untrusted gems.
>
> It is better to have an option to prompt before rewriting a
> file or executing extconf.rb.

Please note that any gem update that needs to replace a stub script
(rake, capistrano, etc) will prompt, so `sudo gem update` will be
pretty annoying.

--=20
Luis Lavena
AREA 17
-
Perfection in design is achieved not when there is nothing more to add,
but rather when there is nothing more to take away.
Antoine de Saint-Exup=E9ry

In This Thread