[ruby-list:47301] [ANN][Security] Ruby 1.8.7 patchlevel 301 released (CVE-2010-0541)

From: Urabe Shyouhei <shyouhei@...>
Date: 2010-08-16 04:09:33 UTC
List: ruby-list #47301
Hello all.  This is a new release for 1.8.7 series.

As Yugui posted earlier, there is a XSS vulnerability in WEBrick HTTP ser=
ver.
 Beware that, though we realized this issue only recently, the CVE-2010-0=
541
has been disclosed for months without notifying us, so public WEBrick ser=
vers
are already under a real threat of attacks.  Many thanks to Hideaki Yaman=
e for
letting us know it.

Anyway we have a fix for the issue now, and here are those applied for th=
e
1.8.7 branch.  All WEBrick users are encouraged to upgrade.

URLs:

ftp://ftp.ruby-lang.org/pub/ruby/1.8/ruby-1.8.7-p301.tar.gz
ftp://ftp.ruby-lang.org/pub/ruby/1.8/ruby-1.8.7-p301.tar.bz2
ftp://ftp.ruby-lang.org/pub/ruby/1.8/ruby-1.8.7-p301.zip

Checksum:

MD5(ruby-1.8.7-p301.tar.gz)=3D 2c1a0c3d3d44e77c958e84ead26b1fc9
SHA256(ruby-1.8.7-p301.tar.gz)=3D
c9e3729fee37299348658c50222bc0317ea0a3cdd5abe6af60a5cb7e06f25edb
SIZE(ruby-1.8.7-p301.tar.gz)=3D 4867903

MD5(ruby-1.8.7-p301.tar.bz2)=3D f461d7672ee99de881f3e9fa5c76fae7
SHA256(ruby-1.8.7-p301.tar.bz2)=3D
6ddd929722d177240c52e9fafa637dae4d7f8a30825faabb33b1c5391b004029
SIZE(ruby-1.8.7-p301.tar.bz2)=3D 4183897

MD5(ruby-1.8.7-p301.zip)=3D 209f447e36207b5989f682008b31e7af
SHA256(ruby-1.8.7-p301.zip)=3D
591c9c6a4210698582fd14f18a715ce19d3a3e4578a7afad2c1e4e126e5cfb0c
SIZE(ruby-1.8.7-p301.zip)=3D 5965403

Thanks,

Attachments (1)

signature.asc (260 Bytes, application/pgp-signature)

In This Thread

Prev Next