From: Yukihiro Matsumoto Date: 2006-05-04T23:21:38+09:00 Subject: Re: (security-related) patch to ALLOC macros to prevent integer overflow bugs Hi, In message "Re: (security-related) patch to ALLOC macros to prevent integer overflow bugs" on Thu, 4 May 2006 10:14:00 +0900, "Dominique Brezinski" writes: |While fixing the integer overflow in rb_ary_fill(), it occurred to me |it would be better to fix the *ALLOC* macros in ruby.h. The patch is |not perfect (though make test-all passes), and I will enumerate the |issues I see with it (most likely a subset of the true issues). Here |is the patch against 1.8.4: 1.9.0 has code against integer overflow attack. If someone could review the code from CVS trunk, I can backport it to 1.8. matz.