From owner-freebsd-security@FreeBSD.ORG Sun Jul 30 18:10:33 2006 Return-Path: X-Original-To: freebsd-security@freebsd.org Delivered-To: freebsd-security@freebsd.org Received: from mx1.FreeBSD.org (mx1.freebsd.org [216.136.204.125]) by hub.freebsd.org (Postfix) with ESMTP id D6C0116A4E0; Sun, 30 Jul 2006 18:10:33 +0000 (UTC) (envelope-from bsd-unix@earthlink.net) Received: from pop-satin.atl.sa.earthlink.net (pop-satin.atl.sa.earthlink.net [207.69.195.63]) by mx1.FreeBSD.org (Postfix) with ESMTP id 8BFA543D46; Sun, 30 Jul 2006 18:10:33 +0000 (GMT) (envelope-from bsd-unix@earthlink.net) Received: from fl-71-54-28-212.dhcp.embarqhsd.net ([71.54.28.212] helo=kt.weeeble.com) by pop-satin.atl.sa.earthlink.net with smtp (Exim 3.36 #1) id 1G7FkA-0005mW-00; Sun, 30 Jul 2006 14:10:26 -0400 Date: Sun, 30 Jul 2006 14:13:24 -0400 From: Randy Pratt To: Frank Steinborn Message-Id: <20060730141324.188a4a8e.bsd-unix@earthlink.net> In-Reply-To: <20060730154733.83EE6B828@shodan.nognu.de> References: <200607280503.k6S53hmW007056@app.auscert.org.au> <20060729163453.GA89895@picobyte.net> <20060730154733.83EE6B828@shodan.nognu.de> X-Mailer: Sylpheed version 2.2.6 (GTK+ 2.8.20; i386-portbld-freebsd6.1) Mime-Version: 1.0 Content-Type: text/plain; charset=US-ASCII Content-Transfer-Encoding: 7bit X-Mailman-Approved-At: Sun, 30 Jul 2006 19:07:48 +0000 Cc: freebsd@auscert.org.au, ports@freebsd.org, freebsd-security@freebsd.org, shaun@FreeBSD.org Subject: Re: Ruby vulnerability? X-BeenThere: freebsd-security@freebsd.org X-Mailman-Version: 2.1.5 Precedence: list List-Id: "Security issues \[members-only posting\]" List-Unsubscribe: , List-Archive: List-Post: List-Help: List-Subscribe: , X-List-Received-Date: Sun, 30 Jul 2006 18:10:33 -0000 On Sun, 30 Jul 2006 17:47:33 +0200 Frank Steinborn wrote: > Shaun Amott wrote: > > On Fri, Jul 28, 2006 at 03:03:43PM +1000, Joel Hatton wrote: > > > > > > FYI, Red Hat released an advisory today about a vulnerability in Ruby. So > > > far it doesn't appear in the VuXML, but am I correct in presuming it will > > > soon? > > > > > > > I've added it; thanks for the report. > > Hmm, i saw the flaw with "portaudit -Fda" yesterday, however - today > my ruby isn't shown as vulnerable anymore. Why? I show it as a vulnerability here. It could be that you may have gotten your last update from a server that hasn't caught up yet. Try running it again and see if that helps. Randy --