From: andrew mcelroy Date: 2013-01-29T06:30:13+09:00 Subject: Re: [SEC][ANN] Rails 3.0.20, and 2.3.16 have been released! --0023544712d053d65c04d45ffb1d Content-Type: text/plain; charset=ISO-8859-1 On Mon, Jan 28, 2013 at 3:13 PM, Aaron Patterson wrote: > Hi everybody. > > I'd like to announce that 3.0.20, and 2.3.15 have been released. These > releases contain one **extremely critical security fix** so please update > **IMMEDIATELY**. > > You can read about the security fix by following this link: > > * [CVE-2013-0333]( > https://groups.google.com/forum/?fromgroups=#!topic/rubyonrails-security/1h2DR63ViGo > ) First, I'd like to thank you Aaron for your hard work in handling security in rails. I can't help but feel that rails is being smacked by major vulnerability after vulnerability. Would it at all be helpful to get a kick starter or some fundraiser started to get a formal audit underway (Where's the NSA when you need them) ? I wonder how much of these vulnerabilities stem from the fact that we (in rails) use turing-complete protocols/languages for everything, thus exposing weird machines. The Science of Insecurity (2008 CCC) It's an hour long, but well worth it- http://www.youtube.com/watch?v=v8F8BqSa-XY While I am glad to see these issues fixed, I can't help but wonder how many more vulnerabilities we still don't know about. Again, I really do appreciate the attention to detail that Aaron and the rest of the rails team give to rails. Respectfully, Andrew McElroy --0023544712d053d65c04d45ffb1d Content-Type: text/html; charset=ISO-8859-1 Content-Transfer-Encoding: quoted-printable On Mon, Jan 28, 2013 at 3:13 PM, Aaron Patterson <tenderlove@ruby-l= ang.org> wrote:
Hi everybody.

I'd like to announce that 3.0.20, and 2.3.15 have been released. =A0The= se releases contain one **extremely critical security fix** so please updat= e **IMMEDIATELY**.

You can read about the security fix by following this link:

* [CVE-2013-0333](https://groups.= google.com/forum/?fromgroups=3D#!topic/rubyonrails-security/1h2DR63ViGo= )

First, I'd like to thank you Aaron for your hard wo= rk in handling security in rails.
I can't help but feel that = rails is being smacked by major=A0vulnerability=A0after=A0vulnerability.
Would it at all be helpful to get a kick starter or some fundraiser st= arted to get a formal audit underway (Where's the NSA when you need the= m)=A0 ?

I wonder how much of these vulnerabilities= stem from the fact that we (in rails) use turing-complete protocols/langua= ges for everything, thus exposing weird machines.

The Science of I= nsecurity (2008 CCC) It's an hour long, but well worth it-=A0http://www.youtube.com/watch= ?v=3Dv8F8BqSa-XY


While I am glad to see these issues fixed, I can't help bu= t wonder how many more vulnerabilities we still don't know about.
Again, I really do=A0appreciate=A0the attention to detail that Aaron a= nd the rest of the rails team give to rails.

Respectfully,
Andrew McElroy

--0023544712d053d65c04d45ffb1d--