From: Tom Copeland Date: 2009-05-13T04:05:53+09:00 Subject: Re: Ruby 1.9.1-p128 is out This release is also mirrored on the RubyForge mirror network: http://rubyforge.org/frs/?group_id=426 Yours, Tom On May 12, 2009, at 3:03 AM, Yugui (Yuki Sonoda) wrote: > -----BEGIN PGP SIGNED MESSAGE----- > Hash: SHA1 > > Good afternoon (JST). Ruby 1.9.1-p128 just has been released. > > This is a patch level release for Ruby 1.9.1. This fixes many bugs and > two security vulnerabilities. This release contains security fix so I > recommend all 1.9.1 users to upgrade your ruby. > > == Location > * http://ftp.ruby-lang.org/pub/ruby/ruby-1.9.1-p129.tar.bz2 > SIZE: 7183891 bytes > MD5: 6fa62b20f72da471195830dec4eb2013 > SHA256: > cb730f035aec0e3ac104d23d27a79aa9625fdeb115dae2295de65355f449ce27 > > * http://ftp.ruby-lang.org/pub/ruby/ruby-1.9.1-p129.tar.gz > SIZE: 9034947 bytes > MD5: c71f413514ee6341c627be2957023a5c > SHA256: > 27b7a8ace1d17cec237020ae9355230b53f8c3875f8d942de903e7d58d14253b > > * http://ftp.ruby-lang.org/pub/ruby/ruby-1.9.1-p129.zip > SIZE: 10299369 bytes > MD5: 156305e9633758eb60b419fabc33b6e4 > SHA256: > 6cbf0eda4ba0afedd8f0bd320e6a14f826149ef517d8bb967149af0558b0743b > > == Security vulnerabilities > * DL::Function#call could pass tainted arguments to a C function > even if > $SAFE > 0. > * DL::dlopen could open a library with tainted library name even if > $SAFE > 0 > > > Thanks, > - -- Yugui (Yuki Sonoda) > -----BEGIN PGP SIGNATURE----- > Version: GnuPG v1.4.9 (Darwin) > Comment: Using GnuPG with Mozilla - http://enigmail.mozdev.org > > iEYEARECAAYFAkoJH0gACgkQOXzH5JLb/AVByACfbqm5u84+VsEIqXu4F/pfABCW > MOcAn0WLOuglc08AWKyeKhSyjGwmZTX5 > =hfog > -----END PGP SIGNATURE----- >