From owner-freebsd-ports@FreeBSD.ORG Sat Jul 29 17:54:17 2006 Return-Path: X-Original-To: ports@freebsd.org Delivered-To: freebsd-ports@FreeBSD.ORG Received: from mx1.FreeBSD.org (mx1.freebsd.org [216.136.204.125]) by hub.freebsd.org (Postfix) with ESMTP id 5F3BB16A4E0; Sat, 29 Jul 2006 17:54:17 +0000 (UTC) (envelope-from remko@freebsd.org) Received: from caelis.elvandar.org (caelis.elvandar.org [217.148.169.59]) by mx1.FreeBSD.org (Postfix) with ESMTP id E928043D45; Sat, 29 Jul 2006 17:54:16 +0000 (GMT) (envelope-from remko@freebsd.org) Received: from localhost (caelis.elvandar.org [217.148.169.59]) by caelis.elvandar.org (Postfix) with ESMTP id 0865992FEA5; Sat, 29 Jul 2006 19:54:16 +0200 (CEST) Received: from caelis.elvandar.org ([217.148.169.59]) by localhost (caelis.elvandar.org [217.148.169.59]) (amavisd-new, port 10024) with ESMTP id 38429-04; Sat, 29 Jul 2006 19:54:15 +0200 (CEST) Message-ID: <44CBA0C8.3080605@FreeBSD.org> Date: Sat, 29 Jul 2006 19:54:16 +0200 From: Remko Lodder User-Agent: Thunderbird 1.5.0.5 (Macintosh/20060719) MIME-Version: 1.0 To: Sergey Matveychuk References: <200607280503.k6S53hmW007056@app.auscert.org.au> <20060729163453.GA89895@picobyte.net> <44CB99E4.2080708@FreeBSD.org> In-Reply-To: <44CB99E4.2080708@FreeBSD.org> Content-Type: text/plain; charset=ISO-8859-1; format=flowed Content-Transfer-Encoding: 7bit X-Virus-Scanned: by the elvandar.org maildomain Cc: Joel Hatton , ports@freebsd.org, freebsd-security@freebsd.org, Shaun Amott Subject: Re: Ruby vulnerability? X-BeenThere: freebsd-ports@freebsd.org X-Mailman-Version: 2.1.5 Precedence: list Reply-To: remko@FreeBSD.org List-Id: Porting software to FreeBSD List-Unsubscribe: , List-Archive: List-Post: List-Help: List-Subscribe: , X-List-Received-Date: Sat, 29 Jul 2006 17:54:17 -0000 Sergey Matveychuk wrote: > Shaun Amott wrote: >> On Fri, Jul 28, 2006 at 03:03:43PM +1000, Joel Hatton wrote: >>> FYI, Red Hat released an advisory today about a vulnerability in Ruby. So >>> far it doesn't appear in the VuXML, but am I correct in presuming it will >>> soon? >>> >> I've added it; thanks for the report. >> > > Can we get patches somewhere? I can't find any. > It is said that the patches are available through the CVSweb but all the information I could fine was in japanese, which is a bit difficult to read for me (read: i do not speak nor read japanese at all). We might have a shot on how different vendors resolved this issue and generate patches from that.. -- Kind regards, Remko Lodder ** remko@elvandar.org FreeBSD ** remko@FreeBSD.org /* Quis custodiet ipsos custodes */