From: Shugo Maeda Date: 2008-08-28T18:19:21+09:00 Subject: Re: DoS vulnerability in REXML Hi, "Gregory Brown" wrote: > On Sat, Aug 23, 2008 at 8:03 PM, Christopher Dicely wrote: > > I don't think the monkeypatch has anything to do with Rails vs. Ruby, > > since there are general instructions for the monkeypatch followed by > > instructions on how to include it in a Rails app. > > It has everything to do with Ruby vs. Rails. > > If we are talking about a vulnerability in standard Ruby, we should be > able to patch standard Ruby and be done with it, not be required to > use some hackish monkeypatch in every application we write.  Ruby core > does of course, maintain Ruby's standard library (or so we hope.) There are some considerations to apply this fix to the Ruby's standard library. This vulnerability (not Ruby specific but in general) had been known for a long time, so we decided to provide a monkey patch for a workaround. We are discussing some considerations on ruby-dev ML, and I'll send a mail with details to ruby-core ML later. Shugo Maeda