From: barjunk Date: 2008-07-04T09:09:14+09:00 Subject: Re: Ruby 1.9.0/1.8.7/1.8.6/1.8.5 new releases (Security Fix) On Jul 3, 11:45 am, Rob Funk wrote: > >>  http://dev.smartleaf.com/misc/p230_fixit_patch.txt > > >> This reverts changeset 17222 from the ruby_1_8_6 branch of the > >> main svn repository, which doesn't *look* security-related, at > >> least at first blush (though it may be a failed backport from > >> another line of development). > > I ran this against the Rails 2.0 and RSpec 1.1.4 test > > suites, no seg faults, no glibc errs, and the same set of tests > > succeeded/passed between this patched version and the stock p111. It ran > > fine against automateit 0.80607 and the various Rails apps I tried. This > > is good. > > I was running Ruby-1.8.6-p230 with this patch for about a week on our > multi-rails-app server, but then came across a problem in an old Rails > app (originally Rails 1.1.6, which we upgraded to 1.2.6 in a failed > attempt at fixing this). > > The problem was in file uploads from an Internet Explorer client.  The > file object's original_filename method was returning just 'Documents, > and the full_original_filename method was returning just '"C:\Documents' > (including the initial double-quotes, but not including the single > quotes), when someone uploaded a file from under their 'C:\Documents and > Settings\' path. > > I switched to Ruby-1.8.6-p111 with the security patches posted above, > and the problem went away. So I've seen a bunch of different ideas about what folks should use...but is there a definitive set of sources to use at this point. Given the short anecdote above and from reading past posts... it seems like I should give 1.8.6-p111 with the patch above a try. Any reasons not to? Mike B.