From: Stanislav Sedov Date: 2008-06-23T20:32:08+09:00 Subject: Re: Ruby 1.9.0/1.8.7/1.8.6/1.8.5 new releases (Security Fix) --Signature=_Mon__23_Jun_2008_15_33_52_+0400_/k8UC=l3YdARUQYi Content-Type: text/plain; charset=US-ASCII Content-Disposition: inline Content-Transfer-Encoding: quoted-printable On Mon, 23 Jun 2008 19:20:00 +0900 Igal Koshevoy mentioned: > Ollivier Robert wrote: > > Try this instead: > > http://www.freebsd.org/cgi/cvsweb.cgi/ports/lang/ruby18/files/ >=20 > Thanks for the assistance. That FreeBSD web site's UI sucks. Their "Get=20 > diffs" button is broken and always returns nothing. To get a diff on a=20 > file, one must click the "text" next to the revision number. >=20 > FreeBSD's backported patch seems insufficient and vulnerable. I come to=20 > this conclusion because they only modified two files (sprintf.c and=20 > string.c) -- but the Ruby changelog for this fix mentions other files=20 > (e.g., array.c), and Zed Shaw identifies about a dozen files potentially= =20 > involved in the fix at=20 > http://www.zedshaw.com/rants/the_big_ruby_vulnerabilities.html > You're not fully correct. All the relevant changes were in array.c and string.c sources, I've backported both. I'm not aware of other security problems in the code. I'll check the link later. --=20 Stanislav Sedov ST4096-RIPE --Signature=_Mon__23_Jun_2008_15_33_52_+0400_/k8UC=l3YdARUQYi Content-Type: application/pgp-signature -----BEGIN PGP SIGNATURE----- Version: GnuPG v2.0.9 (FreeBSD) iEYEARECAAYFAkhfiiAACgkQK/VZk+smlYF0NACfSkIDtCXSJX2ylr/6jPvUvvcO RJwAn3hS4pDAdYCPNM/eRqpiOQ6YOyHq =Khmk -----END PGP SIGNATURE----- --Signature=_Mon__23_Jun_2008_15_33_52_+0400_/k8UC=l3YdARUQYi--