Arbitrary code execution vulnerabilities

P

Peña, Botp

RnJvbTogTWlrZSBCZXJyb3cgW21haWx0bzptYmVycm93MUBwYWNiZWxsLm5ldF0gDQojIFNvbWUg
cGVvcGxlIHNlZW0gdG8gYmUgc2VlaW5nIHByb2JsZW1zIHdpdGggdGhlIDEuOC42LXAyMzAgdXBn
cmFkZSwNCiMgdGhvdWdoLg0KIyBTZWUgY29tbWVudHMgYXQ6DQojIGh0dHA6Ly93ZWJsb2cucnVi
eW9ucmFpbHMuY29tLzIwMDgvNi8yMS9tdWx0aXBsZS1ydWJ5LXNlY3VyaXR5DQojIC12dWxuZXJh
YmlsaXRpZXMNCg0KcnVieSBpcyBub3QgcmFpbHMuIHVwZ3JhZGluZyBydWJ5IGRvZXMgbm90IG1l
YW4geW91J3ZlIHVwZ3JhZGVkIHJhaWxzIHRvby4gd2FpdCBmb3IgdGhlIHJhaWxzIHVwZ3JhZGUu
IGFzayB0aGUgcmFpbHMgbGlzdCBvciBkaGguDQoNCmtpbmQgcmVnYXJkcyAtYm90cA0KDQoNCg==
 
J

Jeremy Kemper

M

M. Edward (Ed) Borasky

Jeremy said:
From: Mike Berrow [mailto:[email protected]]
# Some people seem to be seeing problems with the 1.8.6-p230 upgrade,
# though.
# See comments at:
# http://weblog.rubyonrails.com/2008/6/21/multiple-ruby-security
# -vulnerabilities

ruby is not rails. upgrading ruby does not mean you've upgraded rails too. wait for the rails upgrade. ask the rails list or dhh.

You misunderstood. The latest patchlevels of 1.8.5 and 1.8.6 are segfaulting.

jeremy

1. Is this on simple reproducible cases or do you need Rails to get a
segfault?

2. gdb is your friend. :)
 

Ask a Question

Want to reply to this thread or ask your own question?

You'll need to choose a username for the site, which only take a couple of moments. After that, you can post your question and our members will help you out.

Ask a Question

Members online

No members online now.

Forum statistics

Threads
473,769
Messages
2,569,580
Members
45,055
Latest member
SlimSparkKetoACVReview

Latest Threads

Top