[ruby-list:47208] Re: [ANN][Security] Ruby 1.9.1-p429 is out

From: Urabe Shyouhei <shyouhei@...>
Date: 2010-07-02 13:04:44 UTC
List: ruby-list #47208
(2010/07/02 19:57), Yuki Sonoda (Yugui) wrote:
> The vulnerability does not directly affect to Ruby 1.8 series.

Let me tell you a bit more about it.  This bug does exist on 1.8, but it lacks
ARGF.inplace_mode.  So an attacker should instead utilize ruby's -i option
like this:
  ruby.exe -i? VULNERABLE.rb %VICTIMPATH%

Of course this means the attacker has not only gained privileges to write
files but are also able to spawn arbitrary process;  which means the system
has already been cracked.

So we don't think 1.8 situation itself is a security issue.  We are handling
this as a normal bug.

Attachments (1)

signature.asc (260 Bytes, application/pgp-signature)

In This Thread

Prev Next