[前][次][番号順一覧][スレッド一覧]

ruby:1379

From: "M.Suzuki" <suzk@o...>
Date: Fri, 03 Nov 2006 14:14:42 +0900
Subject: [ruby:1379] Re: DoS脆弱性のニュースの英語版

鈴木と申します。


> 既報の通り、Ruby 1.8.5のcgi.rbにはDoS脆弱性があるのですが、
> このアナウンスはまだ日本語版の公式サイトにしか載っていません。
>
> http://www.ruby-lang.org/ja/news/2006/11/02/CVE-2006-5467/
>
> どなたかこれを英語版に翻訳してくださる方はいませんか?


変な直訳になってるかもしれませんが、叩き台にしてください。


About DoS weakness in CGI library

The weakness that easily caused the state of DoS(Denial Of Service) was
discovered to exist when CGI was made by using this library in CGI library  
(cgi.rb)
  appended to Ruby by the standard.

This weakness is open to the public as CVE-2006-5467.


Existing weak versions

1.8 series
   All versions before 1.8.5

Development version(1.9 series)
   All versions before 2006-09-23


Correspondence method in each version

1.8 series
   Please apply the patch after you update your ruby to 1.8.5.
   9d25f59d1c33a0b215f6c25260dcb536、The size is 367 bytes.

   Moreover, the package of the version that corrects this weakness might be
   being offered severally by each vender who is distributing the package  
of Ruby.
   Please contact each vender about details.

Development version(1.9 series)
   Please update your ruby to the version since 2006-09-23.

-- 
M.Suzuki

--
ML: ruby@m...
使い方: http://QuickML.com/

[前][次][番号順一覧][スレッド一覧]

      1378 2006-11-03 04:39 [maki@r...           ] DoS脆弱性のニュースの英語版             
->    1379 2006-11-03 06:14 ┗[suzk@o...           ]                                       
      1380 2006-11-03 08:18  ┣[maki@r...           ]                                     
      1382 2006-11-03 13:36  ┗[maili31s@c...       ]                                     
      1383 2006-11-04 19:49   ┗[maki@r...           ]                                   
      1384 2006-11-05 14:28    ┗[bsdmad@g...         ]                                 
      1385 2006-11-05 17:04     ┗[maki@r...           ]