From: Stanislav Sedov Date: 2008-06-23T22:58:08+09:00 Subject: Re: Ruby 1.9.0/1.8.7/1.8.6/1.8.5 new releases (Security Fix) --Signature=_Mon__23_Jun_2008_17_59_54_+0400_x=lYu52d8dBfz3A1 Content-Type: text/plain; charset=US-ASCII Content-Disposition: inline Content-Transfer-Encoding: quoted-printable On Mon, 23 Jun 2008 22:38:40 +0900 Hongli Lai mentioned: > Now that you mention it, Keita Yamaguchi sent me an eval.c security=20 > patch a while back. Upon closer inspection it seems that this patch is=20 > not included in the FreeBSD patch set, and neither is bignum.c. eval.c doesn't pose a security fix as safe_level isn't secure by design. It's just a couple of checks around some functions, nothing more. The patch adds another one in eval.c bignum.c fixes an integer overflow at some operations - this can't cause security problems as I could see. It worth applying, though, thanks for info. webrick patches isn't relevant to freebsd in any way, since it fixes a well known security holes in webrick on windows. These holes were worked out a while ago (in fact several month or so). --=20 Stanislav Sedov ST4096-RIPE --Signature=_Mon__23_Jun_2008_17_59_54_+0400_x=lYu52d8dBfz3A1 Content-Type: application/pgp-signature -----BEGIN PGP SIGNATURE----- Version: GnuPG v2.0.9 (FreeBSD) iEYEARECAAYFAkhfrFoACgkQK/VZk+smlYHXTQCeI9gj8l+EORl8UlOto7qHvTct BykAnis6/m6MZBQzhPBGFhGOMhpHEXtz =dFJf -----END PGP SIGNATURE----- --Signature=_Mon__23_Jun_2008_17_59_54_+0400_x=lYu52d8dBfz3A1--