Readers: 0 | Updated: 06-25

Ruby creators warn of serious flaws

Translate Into:

The Ruby programming language, which has become popular as the basis for Web 2.0 sites such as Twitter, contains serious security flaws that could allow attackers to take over an organization's Web server, according to the Ruby development team.

The "disturbing" flaws, which were disclosed on Friday, could affect nearly any typical Ruby-based Web application, according to Thomas Ptacek, founder of security firm Matasano.

The five bugs affect Ruby version 1.8 up to 1.8.7-p21 and version 1.9 up to 1.9.0-1, according to the Ruby development team.

Users can remedy the problem by upgrading to a patched version of Ruby, developers said, with patches available on the Ruby language site.

Popular websites such as Twitter, Scribd, Hulu and the Facebook application Friends for Sale use Ruby, along with the Rails framework, to deploy sophisticated features.

At least three of the published vulnerabilities are easily exploitable and allow normal Ruby code to corrupt the memory of the standard interpreter MRI, Matasano's Ptacek said in an advisory on Friday.

"They involve integer handling errors in the native code backing Ruby's Array, String, and Bignum classes," Ptacek wrote. "These are core classes in Ruby, and don't depend on the libraries or extensions that programs load."

He said organizations running Ruby-based Web applications should upgrade their servers as soon as possible.

"Why is this so disturbing? These vulnerabilities are likely to crop up in just about any average Ruby Web application," he wrote. "The conditions under which the vulnerabilities are exploitable depend on the Ruby programs you are running. But don't gamble. Update as soon as you can."

Techworld is an InfoWorld affiliate.


From The Blogs

InfoWorld RSS Feed

03-06
Model predicts chance of software flaws
Researchers from a German university have developed a model to predict programming errors in applications.The method has the potential to save software companies money by allowing them to isolate part... 查看全文

One Big Health Nut

06-25
Relaxation alleviates stress and averts serious health problems
When you think about health, lying around is probably not the first activity (or lack there of) that comes to mind.  But it should still be on your mental ‘To do’ list.  Relaxation is an essential ele... 查看全文

In The Field

11-13
ASHG Guest post: Are we serious about education, or not?
As a special treat, I’ve got a guest post from former genetics editor at Nature Chris Gunter.She’s also twittering the event here. How hip!Aravinda Chakravarti’s presidential address was, of course, t... 查看全文

Yanko Design

02-27
Some Serious Rocking
ID people love the tools afforded to them by todays advance computers and software. Theyre able to visualize products and test every nuance before manufacturing. Such is the case with the MORPHOGENESI... 查看全文

Jalopnik

11-14
GM's Mark LaNeve Drops Dealer Missive Begging Congress For Mercy, Serious Financial Help [Financiapocalypse]
Hot on the heels of yesterday's e-mail plea to employees from GM's Troy Clarke comes the following e-mail from GM's Mark LaNeve. The General's marketing maven e-mailed dealers asking for them to make ... 查看全文

Sports - Channel Feed

11-18
Donovan McNabb Was Serious
National Football League Blogcast, NFL Blogcast Philadelphia Eagles quarterback Donovan McNabb said he didn’t realize an NFL game could end in a tie. This after the Eagles and Cincinnati Bengals fough... 查看全文

Sports - Channel Feed

11-18
Earnest Graham Ankle Injury Serious
National Football League Blogcast, NFL Blogcast Tampa Bay Bucs running back Earnest Graham, who leads the team in rushing yards and touchdowns, might be finished for the 2008 season with an ankle inju... 查看全文

Celebrity Gossip from Celebridiot

11-20
Victoria Beckham is sexy and serious at Beso
Victoria Beckham arrived at Beso in Hollywood last night to attend a private party and she was looking sexy.  She was working a super tight white dress that didnt leave much to the imagination, but sh... 查看全文

Celebrity gossip juicy celebrity rumors Hollywood gossip blog from Perez Hilton

11-20
Tom Cruise's 'Serious' Nazi Film Garners Unintended Laughs
The train wreck that is Tom Cruise's Nazi flick, Valkyrie, will finally be in theaters in a little over a month. We sure can't wait to see it. Not! A few folks who've had the honor of seeing it before... 查看全文

Celebrity gossip juicy celebrity rumors Hollywood gossip blog from Perez Hilton

11-21
It's Getting Serious! Maniston Introduces John To The Fam
So will it be wedding bells or baby bonnets for John Mayer and Jennifer Aniston? There's been a huge development in the John and Jen homance! The music guy was introduced to Maniston's daddy, soap act... 查看全文
More Articles