From: Igal Koshevoy Date: 2008-06-24T18:11:58+09:00 Subject: Re: Ruby 1.9.0/1.8.7/1.8.6/1.8.5 new releases (Security Fix) We have another potential winning solution! Can someone please review this patch and provide advice of the pros/cons of using this solution versus the Smartleaf patch described in the previous email? In a nutshell, Stanislav and Hongli's solution is a backport of fixes to p111, while the Smartleaf solution fixes the segfaults in p230. Also, can anyone get through to the official Ruby maintainers? It's awesome that we can create two unofficial patches on short notice like this, but I'd really like to have them involved in this. > Hongli Lai wrote: >> Now that you mention it, Keita Yamaguchi sent me an eval.c security >> patch a while back. Upon closer inspection it seems that this patch is >> not included in the FreeBSD patch set, and neither is bignum.c. > The analysis Zed Shaw described in his blog was based on reviewing all > the changes made this month. Although this is more time consuming, it > also seems like the most methodical way of making sure we catch all the > relevant changes. > >> I've made an updated patch set: >> http://blog.phusion.nl/assets/r8ee-security-patch-20080623-2.txt I ran this against the Rails 2.0 and RSpec 1.1.4 test suites, no seg faults, no glibc errs, and the same set of tests succeeded/passed between this patched version and the stock p111. Excellent. I also ran this and the smartleaf version against RubySpecs, and got identical results to those of a stock p111. Excellent. As far as I can tell, both of these patches provide a working version of MRI Ruby. Stanislav and Hongli's p111 backport relies on them having correctly cherry-picked the right fixes. Smartleaf's p230 fix relies on the rest of that Ruby version to be correct, and I have some concerns about other lurking bugs if they shipped a version with such an obvious flaw. How do we choose between these? -igal -- Posted via http://www.ruby-forum.com/.