From: Eric Hodel Date: 2006-08-11T02:12:27+09:00 Subject: Re: [ANN] Rails 1.1.5: Mandatory security patch (and other tidbits) On Aug 10, 2006, at 9:58 AM, William Grosso wrote: > So, let's pretend for a moment that sometime within the next 24 > hours, an > "official" explanation of the patch comes out. We'll then have seen > the > following sequence: > > 1. Rails team notices issue and fixes issue. > 2. Rails team issues patch and announces patch to community. > 3. Rails team pauses while patch disseminates through world. > Developers > who are really concerned about what the patch might contain have > complete > access to changelogs and sourcecode and can figure out what's being > changed. > 4. Rails team explains patch withing 48 hours > > This is *good* performance. Whether or not it's open source or > commercial, > this is good performance. The pause while the patch was > disseminated was > probably the right action (certainly, any other course of action > would have > been more questionable, and put more applications at risk). > > They've given us an amazing framework, and they're behaving > responsibly. > > I, for one, want to publicly say "Thank you." This is the fourth vulnerability that I know in Rails of but the first that has been fully acknowledged as such. Two were DOSs (one which I discovered, one which was co-discovered by my company), the third was described as a DOS but potentially was a vulnerability of the same severity as this one. -- Eric Hodel - drbrain@segment7.net - http://blog.segment7.net This implementation is HODEL-HASH-9600 compliant http://trackmap.robotcoop.com