Friday, January 11, 2013

[Rails] Re: Rails exploit in multi_xml remote code execution monkeypatch

After I sobered up, it's actually just anything that ends up using multi_xml.

Sorry for any confusion. :/

~Spaceghost

On Thursday, January 10, 2013 7:28:12 PM UTC-5, Spaceghost wrote:
Our friend the fowlest of ducks put together a nice monkeypatch for us to require after multi_xml is required.

This affects any rails project, any project using activesupport, possibly more.

https://gist.github.com/d7f6d9f4925f413621aa

You probably won't need help with applying it, but here's an update on a proper fix. Should be in by Saturday perhaps.

I'm also going to take this chance to be that guy and say retweet this if you can. https://twitter.com/fowlduck/status/289514566558310401

~Spaceghost

--
You received this message because you are subscribed to the Google Groups "Ruby on Rails: Talk" group.
To post to this group, send email to rubyonrails-talk@googlegroups.com.
To unsubscribe from this group, send email to rubyonrails-talk+unsubscribe@googlegroups.com.
To view this discussion on the web visit https://groups.google.com/d/msg/rubyonrails-talk/-/7IK5XMOsxx8J.
For more options, visit https://groups.google.com/groups/opt_out.
 
 

0 Comments:

Post a Comment

Subscribe to Post Comments [Atom]

<< Home


Real Estate