JRuby

REXML DOS issue in Ruby 1.8 libraries

Details

  • Type: Bug Bug
  • Status: Closed Closed
  • Priority: Major Major
  • Resolution: Fixed
  • Affects Version/s: JRuby 1.1.4
  • Fix Version/s: JRuby 1.1.5
  • Component/s: Miscellaneous
  • Labels:
    None
  • Number of attachments :
    0

Description

See here: http://www.infoq.com/news/2008/08/rexml-entity-explosion-dos-fix

There are patches available. For 1.1.5.

Activity

Hide
Charles Oliver Nutter added a comment -

Tracked down the commit to Ruby's repo to r19033, and applied the same to our repo with a slight modification to add the rexml document test. Committed in r7899.

Show
Charles Oliver Nutter added a comment - Tracked down the commit to Ruby's repo to r19033, and applied the same to our repo with a slight modification to add the rexml document test. Committed in r7899.

People

Vote (0)
Watch (1)

Dates

  • Created:
    Updated:
    Resolved: