Ruby 1.9.3-p286 is released

Ruby 1.9.3-p286 is released.

This release includes some security fixes, and other many bug fixes.

See ticktes and ChangeLog for details.

Continue Reading…

$SAFE escaping vulnerability about Exception#to_s / NameError#to_s (CVE-2012-4464, CVE-2012-4466)

Vulnerabilities found for Exception#to_s, NameError#to_s, and name_err_mesg_to_s() which is Ruby interpreter-internal API. A malicious user code can bypass $SAFE check by utilizing one of those security holes.

Continue Reading…

Other News

More News…