« Two vulnerabilities fixed in Rails 2.3.4 | Main | Vulnerability in Rails 2.3 HTTP Authentication »
Wednesday
Jun102009

DoS vulnerability in BigDecimal

A Denial of Service (DoS) vulnerability was found in the BigDecimal standard Ruby library. An attacker could cause a segmentation fault and crash the Ruby interpreter. This is due to the BigDecimal method mishandling certain large values. Almost every Rails application is vulnerable to this because ActiveRecord relies on this method.

You are advised to update your Ruby installation. There is a temporary fix on Github. This fix breaks valid formats supported by BigDecimal, so you are advised to plan migrating to a new Ruby version.

PrintView Printer Friendly Version

EmailEmail Article to Friend

Reader Comments (6)

Even if you do correctly identify a DoS or DDoS attack, it is unlikely that you will be able to determine the actual target or source of the attack!

May 7, 2010 | Unregistered CommenterBathrooms Sheffield

This Bottega Veneta Pleated Woven Tote is kind of big at about 11? x 11 x 6? and it really is adequate to carry your daily stuff. It has an open top to let you maximize its space, plus interior zip and cell phone pockets sit on the exact suede lining for storage. The exact handles are adjustable with buckle closure for you to carry this replica handbags Monogram Shimmer with ease.gmt watches replicas

August 18, 2010 | Unregistered Commentervannas

The exact handles are adjustable with buckle closure for you to carry this replica handbags Monogram Shimmer with ease

Thanks for the advise. We should really careful from the attackers and update our Ruby installation to prevent from attackers in future. Cement Siding Richmond

August 21, 2010 | Unregistered CommenterAbdul Saeed

To block the attackers from attacking the Ruby Installation and caused any damage to the installation its really a nice suggestion by Heiko to update the Ruby Installation with the latest version.6x8 Car Speakers

August 23, 2010 | Unregistered CommenterSaeed

A typical look at does reflects your wealth, status and ability..replica hermes|

September 1, 2010 | Unregistered CommenterWholesale

PostPost a New Comment

Enter your information below to add a new comment.

My response is on my own website »
Author Email (optional):
Author URL (optional):
Post:
 
Some HTML allowed: <a href="" title=""> <abbr title=""> <acronym title=""> <b> <blockquote cite=""> <code> <em> <i> <strike> <strong>