blog comments 0 del.icio.us bookmarks 0 diggs 0 Google results 0

8.3
PostRank

Multiple Ruby security vulnerabilities

Riding Rails - home From Riding Rails - home, 3 months ago, 4 views

Drew Yao at Apple uncovered a handful of nasty security vulnerabilities affecting all current versions of Ruby. The details are still under wraps because an attacker can DoS you or possibly execute arbitrary code—holy crap! Better upgrade sooner than later.

According to the official Ruby security advisory, the vulnerable Rubies are:

Those of us running Ruby 1.8.4 or earlier must upgrade to 1.8.5 or later for a fix. Those on 1.8.5-7 can grab the latest patchlevel release for a fix.

(Please note: Ruby 1.8.7 breaks backward compatibility and is only compatible with Rails 2.1 and later, so don’t go overboard!)

comments

No comments yet.

You must be logged in to add your own comment.