From: Gregory Brown Date: 2008-08-24T08:52:50+09:00 Subject: Re: [ANN] DoS vulnerability in REXML On Sat, Aug 23, 2008 at 7:37 PM, Urabe Shyouhei wrote: > James Britt wrote: >> Then the original post is misleading in emphasizing Rails. >> >> Lots of people use REXML on the Web outside of Rails, so the effect on >> Rails is incidental to the real problem and should have been omitted >> for clarity. > > Incidental yes, but that doesn't mean Rails users must be ignored. > Perhaps web-admins should not omit Rails workarounds, but also add a > note that non-Rails apps can suffer this issue. But really, the case is "Any Ruby code parsing user passed XML", which is in no way limited to Rails. It's reasonable to say "Hey Rails kids, this means you!", but I think it's a little misleading to pass it off as a Rails bug with a monkeypatch rather than a patch against Ruby itself. -greg -- Technical Blaag at: http://blog.majesticseacreature.com | Non-tech stuff at: http://metametta.blogspot.com