pkgsrc-Changes archive

[Date Prev][Date Next][Thread Prev][Thread Next][Date Index][Thread Index][Old Index]

CVS commit: pkgsrc/lang/ruby18-base



Module Name:    pkgsrc
Committed By:   taca
Date:           Mon Feb 21 14:35:38 UTC 2011

Modified Files:
        pkgsrc/lang/ruby18-base: distinfo

Log Message:
Update ruby18-base package to 1.8.7.334 (Ruby 1.8.7p334).

* The FileUtils Vulnerability

        
http://www.ruby-lang.org/en/news/2011/02/18/fileutils-is-vulnerable-to-symlink-race-attacks/

* The $SAFE Vulnerability

Fri Feb 18 21:18:55 2011  Shugo Maeda  <shugo%ruby-lang.org@localhost>

        * test/ruby/test_exception.rb 
(TestException::test_to_s_taintness_propagation):
          Test for below.

Fri Feb 18 21:18:55 2011  URABE Shyouhei  <shyouhei%ruby-lang.org@localhost>

        * error.c (exc_to_s): untainted strings can be tainted via
          Exception#to_s, which enables attackers to overwrite sane strings.
          Reported by: Yusuke Endoh <mame at tsg.ne.jp>.

        * error.c (name_err_to_s): ditto.

Fri Feb 18 21:17:22 2011  Shugo Maeda  <shugo%ruby-lang.org@localhost>

        * lib/fileutils.rb (FileUtils::remove_entry_secure): there is a
          race condition in the case where the given path is a directory,
          and some other user can move that directory, and create a
          symlink while this method is executing.
          Reported by: Nicholas Jefferson <nicholas at pythonic.com.au>

Fri Feb 18 19:46:46 2011  NAKAMURA Usaku  <usa%ruby-lang.org@localhost>

        * win32/win32.c (init_stdhandle): backport mistake of r29382.
          some code are needless in ruby 1.8.
          [ruby-core:34579]

Fri Feb 18 19:22:17 2011  URABE Shyouhei  <shyouhei%ruby-lang.org@localhost>

        * configure.in: revert revision r29854.  This revision introduced
          binary incompatibilities on some circumstances.  The bug that
          revision was fixing gets reopened by this reversion.
          [ruby-dev:43152] cf. [Bug #2553]


To generate a diff of this commit:
cvs rdiff -u -r1.46 -r1.47 pkgsrc/lang/ruby18-base/distinfo

Please note that diffs are not public domain; they are subject to the
copyright notices on the relevant files.



Home | Main Index | Thread Index | Old Index