From: Dominique Brezinski Date: 2006-05-05T02:45:10+09:00 Subject: Re: (security-related) patch to ALLOC macros to prevent integer overflow bugs On 5/4/06, Yukihiro Matsumoto wrote: > Hi, > > In message "Re: (security-related) patch to ALLOC macros to prevent integer overflow bugs" > on Thu, 4 May 2006 10:14:00 +0900, "Dominique Brezinski" writes: > > |While fixing the integer overflow in rb_ary_fill(), it occurred to me > |it would be better to fix the *ALLOC* macros in ruby.h. The patch is > |not perfect (though make test-all passes), and I will enumerate the > |issues I see with it (most likely a subset of the true issues). Here > |is the patch against 1.8.4: > > 1.9.0 has code against integer overflow attack. If someone could > review the code from CVS trunk, I can backport it to 1.8. > > matz. Great! I will try to look it over when I get a chance. As an aside, I didn't like the macro hack either ;)