Add comment

Mar 04 2008
User: cedric
Category: Techno
Tags: ruby vulnerability webrick

File access vulnerability of WEBrick

WEBrick, a standard library of Ruby to implement HTTP servers, has file access vulnerability.

Impact

The following programs are vulnerable.

  • Programs that publish files using WEBrick::HTTPServer.new with the :DocumentRoot option
  • Programs that publish files using WEBrick::HTTPServlet::FileHandler

Affected systems are:

  • Systems that accept backslash (\) as a path separator, such as Windows.
  • Systems that use case insensitive filesystems such as NTFS on Windows, HFS on Mac OS X.

1.8 series Please upgrade to 1.8.5-p115 or 1.8.6-p114.

1.9 series Please apply the following patch to lib/webrick/httpservlet/filehandler.rb.

Announcement

comments : 0 Add comment




Back
Log in

Quick links

Localization

Search

weather


  • metric us

gallery

Last comments

Categories

  • categories

nabaztag

  • message

    left
    right
    voice
    speed
    pitch

hcard