From: Christian Neukirchen Date: 2006-08-11T00:48:00+09:00 Subject: Re: [ANN] Rails 1.1.5: Mandatory security patch (and other tidbits) khaines@enigo.com writes: > The core issue is that releasing a patch to fix a critical security > vulnerability without telling anyone what the vulnerability is does very > little good as a knowledgeable cracker can just SVN diff the new version > with the old one and peruse that patch to have an exploit ready to go." Alternatively, you (or everyone else with a bit experience of Ruby) can svn diff yourself. Or, you can search for third-party information about the hole, and soon will find something like: http://blog.evanweaver.com/articles/2006/08/10/explanation-of-the-rails-security-vulnerability-in-1-1-4-others There you have a clear explanation which you can prove by looking at the code yourself, see if your own application is affected (of course it's not, you do the routing thing in a sane way) and have learned something for the future. Just because there is a Rails core team that advises you to update, there is no reason to think yourself. Given their authority, you should believe what they say about Rails is true, but that won't and shouldn't stop you from checking yourself. -- Christian Neukirchen http://chneukirchen.org