From: Urabe Shyouhei Date: 2010-07-02T22:04:44+09:00 Subject: Re: [ANN][Security] Ruby 1.9.1-p429 is out --------------enig633B6BE7BD0BA4825C1FD0FF Content-Type: text/plain; charset=ISO-2022-JP Content-Transfer-Encoding: quoted-printable (2010/07/02 19:57), Yuki Sonoda (Yugui) wrote: > The vulnerability does not directly affect to Ruby 1.8 series. Let me tell you a bit more about it. This bug does exist on 1.8, but it = lacks ARGF.inplace_mode. So an attacker should instead utilize ruby's -i optio= n like this: ruby.exe -i? VULNERABLE.rb %VICTIMPATH% Of course this means the attacker has not only gained privileges to write= files but are also able to spawn arbitrary process; which means the syst= em has already been cracked. So we don't think 1.8 situation itself is a security issue. We are handl= ing this as a normal bug. --------------enig633B6BE7BD0BA4825C1FD0FF Content-Type: application/pgp-signature; name="signature.asc" Content-Description: OpenPGP digital signature Content-Disposition: attachment; filename="signature.asc" -----BEGIN PGP SIGNATURE----- Version: GnuPG v1.4.10 (MingW32) Comment: Using GnuPG with Mozilla - http://enigmail.mozdev.org/ iEYEARECAAYFAkwt4+gACgkQuTXPUnA5eMKdZwCfdxKg7AnTR66k5JfW+hglJFYV N/sAmgJ7ziCKH/Dgm0koCNRtvvRvu+nA =Pt5b -----END PGP SIGNATURE----- --------------enig633B6BE7BD0BA4825C1FD0FF--