From: Christopher Dicely Date: 2008-08-24T08:58:07+09:00 Subject: Re: [ANN] DoS vulnerability in REXML On Sat, Aug 23, 2008 at 4:37 PM, Urabe Shyouhei wrote: > James Britt wrote: >> Then the original post is misleading in emphasizing Rails. >> >> Lots of people use REXML on the Web outside of Rails, so the effect on >> Rails is incidental to the real problem and should have been omitted >> for clarity. > > Incidental yes, but that doesn't mean Rails users must be ignored. > Perhaps web-admins should not omit Rails workarounds, but also add a > note that non-Rails apps can suffer this issue. > > The notice on the ruby-lang.org includes the general workaround and the Rails-specific instructions (the monkeypatch is general, there is a special mechanism for guaranteeing it is included given for Rails.) The problem with the notice is that it the beginning part that announces the problem makes it sound like it is in a Rails component, when it is in the Ruby Standard Library. Instead of this: ---[begin] There is a DoS vulnerability in the REXML library used by Rails to parse incoming XML requests. A so-called "XML entity explosion" attack technique can be used for remotely bringing down (disabling) any application which parses user-provided XML. Most Rails applications will be vulnerable to this attack. ---[end] It should say something like this: ---[begin] There is a DoS vulnerability in the REXML library included in the Ruby Standard Library. A so-called "XML entity explosion" attack technique can be used for remotely bringing down (disabling) any application which parses user-provided XML using REXML. ---[end] Any specific notes about systems that rely on REXML (including Rails) should have followed that accurate description of the nature and applicability of the problem. (I also question whether its true that "Most Rails applications will be vulnerable to this attack", is it really true that the majority of Rails apps consume XML from untrusted sources?