Topicfire Ruby on Rails News http://topicfire.com/Ruby-on-Rails 2013-05-25T10:49:13+00:00 text/html 2013-05-21T15:01:39+00:00 http://on-ruby.blogspot.com/ Post-its and Interviews Part 1 http://on-ruby.blogspot.com/2013/05/post-its-and-interviews-part-1.html <a href="http://on-ruby.blogspot.com/2013/05/post-its-and-interviews-part-1.html"><img src="http://4.bp.blogspot.com/_RqmfLIaz-o4/SZ6bU6fEXYI/AAAAAAAAAC0/TrCRgcZTVZk/S45/andyo_2008_02_web.jpeg" /></a><br />I was in a meeting room I'd not visited before the other day and I saw a great idea on the wall. At a glance, I saw what another team had been doing.  With a little more thought and discussion with a co-worker, I was able to build a more... text/html 2013-05-14T18:33:57+00:00 http://www.ruby-lang.org/ Ruby 1.9.3-p429 is released http://www.ruby-lang.org/en/news/2013/05/14/ruby-1-9-3-p429-is-released/ Now Ruby 1.9.3-p429 is released. We once released p426 some hours before, but it had build problems on some platforms. Use this p429 instead, please. This release includes a security fix about bundled DL / Fiddle. Object taint bypassing in DL and Fiddle in Ruby (CVE-2013-2065) And some small bugfixes are also included. See... text/html 2013-05-14T14:35:20+00:00 http://www.ruby-lang.org/ Object taint bypassing in DL and Fiddle in Ruby (CVE-2013-2065) http://www.ruby-lang.org/en/news/2013/05/14/taint-bypass-dl-fiddle-cve-2013-2065/ There is a vulnerability in DL and Fiddle in Ruby where tainted strings can be used by system calls regardless of the $SAFE level set in Ruby. This vulnerability has been assigned the CVE identifier CVE-2013-2065. Impact Native functions exposed to Ruby with DL or Fiddle do not check the taint values set on the... text/html 2013-05-14T14:35:19+00:00 http://www.ruby-lang.org/ Ruby 2.0.0-p195 is released http://www.ruby-lang.org/en/news/2013/05/14/ruby-2-0-0-p195-is-released/ Ruby 2.0.0-p195 is released. This is the first patchlevel release of 2.0.0. This release include a security fix of Ruby DL/Fiddle extension. Object taint bypassing in DL and Fiddle in Ruby(CVE-2013-2065) And there’re many bug-fixes and some optimization, and documentation fixes. Downloads ftp://ftp.ruby-lang.org/pub/ruby/2.0/ruby-2.0.0-p195.tar.bz2 SIZE:... text/html 2013-05-14T14:35:18+00:00 http://www.ruby-lang.org/ Ruby 1.9.3-p426 is released http://www.ruby-lang.org/en/news/2013/05/14/ruby-1-9-3-p426-is-released/ Now Ruby 1.9.3-p426 is released. This release includes a security fix about bundled DL / Fiddle. Object taint bypassing in DL and Fiddle in Ruby (CVE-2013-2065) And some small bugfixes are also included. See tickets and ChangeLog for details. Download You can download this release from: ftp://ftp.ruby-lang.org/pub/ruby/1.9/ruby-1.9.3-p426.tar.bz2 ...