Spaceghost
2013-Jan-11 00:28 UTC
Rails exploit in multi_xml remote code execution monkeypatch
Our friend the fowlest of ducks put together a nice monkeypatch for us to require after multi_xml is required. This affects any rails project, any project using activesupport, possibly more. https://gist.github.com/d7f6d9f4925f413621aa You probably won''t need help with applying it, but here''s an update on a proper fix. Should be in by Saturday perhaps. https://twitter.com/sferik/status/289474598070792192 I''m also going to take this chance to be that guy and say retweet this if you can. https://twitter.com/fowlduck/status/289514566558310401 ~Spaceghost -- You received this message because you are subscribed to the Google Groups "Ruby on Rails: Talk" group. To post to this group, send email to rubyonrails-talk-/JYPxA39Uh5TLH3MbocFF+G/Ez6ZCGd0@public.gmane.org To unsubscribe from this group, send email to rubyonrails-talk+unsubscribe-/JYPxA39Uh5TLH3MbocFF+G/Ez6ZCGd0@public.gmane.org To view this discussion on the web visit https://groups.google.com/d/msg/rubyonrails-talk/-/LXUJruo4N5cJ. For more options, visit https://groups.google.com/groups/opt_out.
Spaceghost
2013-Jan-11 09:50 UTC
Re: Rails exploit in multi_xml remote code execution monkeypatch
After I sobered up, it''s actually just anything that ends up using multi_xml. Sorry for any confusion. :/ ~Spaceghost On Thursday, January 10, 2013 7:28:12 PM UTC-5, Spaceghost wrote:> > Our friend the fowlest of ducks put together a nice monkeypatch for us to > require after multi_xml is required. > > This affects any rails project, any project using activesupport, possibly > more. > > https://gist.github.com/d7f6d9f4925f413621aa > > You probably won''t need help with applying it, but here''s an update on a > proper fix. Should be in by Saturday perhaps. > https://twitter.com/sferik/status/289474598070792192 > > I''m also going to take this chance to be that guy and say retweet this if > you can. https://twitter.com/fowlduck/status/289514566558310401 > > ~Spaceghost >-- You received this message because you are subscribed to the Google Groups "Ruby on Rails: Talk" group. To post to this group, send email to rubyonrails-talk-/JYPxA39Uh5TLH3MbocFF+G/Ez6ZCGd0@public.gmane.org To unsubscribe from this group, send email to rubyonrails-talk+unsubscribe-/JYPxA39Uh5TLH3MbocFF+G/Ez6ZCGd0@public.gmane.org To view this discussion on the web visit https://groups.google.com/d/msg/rubyonrails-talk/-/7IK5XMOsxx8J. For more options, visit https://groups.google.com/groups/opt_out.