Posted by usa on 22 Feb 2013 ruby ã«ãã³ãã«ããã¦ãã JSON ã«é¢ãã¦ããµã¼ãã¹ä¸è½æ»æ (DoS) ããã³å®å ¨ã§ãªããªãã¸ã§ã¯ãã®çæãå¯è½ã¨ããèå¼±æ§ãå ±åããã¾ããã ãã®èå¼±æ§ã¯ CVE-2013-0269 ã¨ã㦠CVE ã«ç»é²ããã¦ãã¾ãã ã¦ã¼ã¶ã¼ã®çããã«ã¯ ruby ãæ´æ°ãããã¨ãå¼·ããå§ããã¾ãã 詳細 対象ã®ã·ã¹ãã ã« JSON ããã¥ã¡ã³ãããã¼ã¹ãããéã«ãJSON gem (ruby ã«ãã³ãã«ããã¦ãããã®ãå«ã) ã«å¯¾ã㦠Ruby ã® Symbol ãªãã¸ã§ã¯ããçæããããã¨ãã§ãã¾ãã Ruby 㯠Symbol ãªãã¸ã§ã¯ããã¬ã¼ããã¸ã³ã¬ã¯ã·ã§ã³ã§ååããªãã®ã§ãçµæã¨ãã¦ãµã¼ãã¹ä¸è½æ»æãæç«ãå¾ã¾ãã åããã¯ããã¯ãå©ç¨ãã対象ã®ã·ã¹ãã ã«ãªãã¸ã§ã¯ããçæãããå é¨ã®ãªãã¸ã§ã¯ãã®ããã«æ±ããããã¨ã
ã¡ã³ããã³ã¹
ãç¥ãã
é害
ãªãªã¼ã¹ãé害æ å ±ãªã©ã®ãµã¼ãã¹ã®ãç¥ãã
ææ°ã®äººæ°ã¨ã³ããªã¼ã®é ä¿¡
å¦çãå®è¡ä¸ã§ã
j次ã®ããã¯ãã¼ã¯
kåã®ããã¯ãã¼ã¯
lãã¨ã§èªã
eã³ã¡ã³ãä¸è¦§ãéã
oãã¼ã¸ãéã
{{#tags}}- {{label}}
{{/tags}}