Stories
Slash Boxes
Comments
typodupeerror delete not in

+-   Apple finds multiple security holes in Ruby-> on Sunday June 22 2008, @08:20PM ruphus13

Submitted by ruphus13 on Sunday June 22 2008, @08:20PM
security
ruphus13 writes "Ruby continues to be in the spotlight, but this time for the wrong reasons. "A member of Apple's security team has discovered multiple serious security vulnerabilities in Ruby, the popular open-source scripting language. According to an advisory on the Ruby project site, Apple's Drew Yao reported at least six of the vulnerabilities, which can be exploited to cause a denial-of-service condition or the execution of arbitrary code." The article goes on to state, "These vulnerabilities are likely to crop up in just about any average ruby web application. And by "crop up" I mean "crop up exploitable from trivial user-specified parameters". It's not hard to begin imagining cases where Ruby/Rails programmers use code similar to the samples above to routinely handle user input.""
Link to Original Source
submission

This discussion was created for logged-in users only, but now has been archived. No new comments can be posted.
The Fine Print: The following comments are owned by whoever posted them. We are not responsible for them in any way.
 Full
 Abbreviated
 Hidden
More
Loading... please wait.
Every man is as God made him, ay, and often worse. -- Miguel de Cervantes