Ruby 1.9.3-p392 is released (includes two security fixes)

73 views
Skip to first unread message

m...@state.io

unread,
Feb 24, 2013, 4:07:33 PM2/24/13
to rubysec-...@googlegroups.com
Hello,

Ruby 1.9.3-p392 was released on Friday and includes 2 security patches.

- Denial of Service and Unsafe Object Creation Vulnerability in JSON  (CVE-2013-0269)

- Entity expansion DoS vulnerability in REXML (XML bomb)

More information here: http://www.ruby-forum.com/topic/4411203

- Max Veytsman
Reply all
Reply to author
Forward
0 new messages