4 ms·
Multiple Ruby security vulnerabilities
- comatose_kid 18y agotptacek's blog has some good info on this: http://www.matasano.com/log/1070/updates-on-drew-yaos-terrible-ruby-vulnerabilities/ http://www.matasano.com/log/1070/updates-on-drew-yaos-terrib...
- timr 18y agoAnyone successfully running the patched version w/o segfaults?
- chaostheory 18y agolooks like this is a common prob... I guess i need to migrate to jruby sooner than I thought
- tptacek 18y agoBoth String and Array have integer overflows. If an attacker can control the size of a string or the index to a string or an array, they can control the address in native memory where Ruby will write data. The details of these vulnerabilities are not under wraps; they were fixed in commits labelled with their CVE numbers.
- ROFISH 18y agoa = Array.new a[0x7fffffff] = 55 (irb):14: [BUG] Segmentation fault Presumably this is one of the attack vectors that was fixed.
- tptacek 18y agoYes, it was. Go look what happens in gdb when you do that.
- gaika 18y agoI'm getting a different error with x86_64, but probably not protected against other bugs: (irb):3:in `[]=': failed to allocate memory (NoMemoryError) from (irb):3:in `irb_binding' from /usr/lib/ruby/1.8/irb/workspace.rb:52:in `irb_binding' from /usr/lib/ruby/1.8/irb/workspace.rb:52
- tptacek 18y agosizeof(long) is different for you, and fixnum is 63(?) bits. Try 0x7fffffffffffffff.
- dfranke 18y agoHere's a fix for etch, since the security team hasn't released an advisory yet: http://dfranke.us/rubyfix.txt http://dfranke.us/rubyfix.txt