注æåèµ·ã®è¨äº ãæ³¨æåèµ·ãã§ã¯ãã©ãã¯ãææ¡ããèå¼±æ§ãã©ã³ãµã ã¦ã§ã¢ãªã©ãµã¤ãã¼æ»æã«é¢ããæ å ±ããã¡æ©ãçºä¿¡ãã¾ãã 解説ããã®ã¯ããµã¤ãã¼ææ¥ã»ã³ã¿ã¼ãã»ãã¥ãªãã£ç£è¦ã»ã³ã¿ã¼ï¼JSOCï¼ãã»ãã¥ãªãã£è¨ºæãã¼ã ãªã©ã®å°éå®¶ã§ãã
èå¼±æ§å±åºå¶åº¦ã§å³æ¸é¤¨ã·ã¹ãã ã®èå¼±æ§ãå±ãã¦ã製åã®èå¼±æ§ã¨ãã¦æ±ãããªãï¼ãµã¤ãã®èå¼±æ§ã¨ãã¦æ±ãããï¼çç±ã¯ãB2Bã§éãã製åã ãããå¶åº¦ã®æ ¹æ ã®çµç£çå示ãé©ç¨ç¯å²ãã被害ãä¸ç¹å®å¤æ°ã®è ã«ãã¨ãã¦ããããã«ãB2Bã§è§£æ±ºããªãåé¡ã¸ã®åçµã ããã #librahack
ã¯ããRuby 1.9.2ããªãªã¼ã¹ããã¾ãããããã®ãã¼ã¸ã§ã³ã§ã¯WEBrick ã«ã¼ããã¤æ»æå¯è½ãªèå¼±æ§ - ã¹ã©ãã·ã¥ãããã»ã¸ã£ãã³ã§ç´¹ä»ããã¦ããèå¼±æ§ãåãæ¸ãããããã§ä¿®æ£ããã¦ãããããªã®ã§ããã©ããããããªãã§åãä¿®æ£ãã¦ããã®ããã£ã¦é¡æ«ãããã¨é¢ç½ãã®ã§ç´¹ä»ãã¾ãã Appleãupstreamã«å ±åãã¦ãããªãã¾ã¾èå¼±æ§ãCVEã«å±ãåºã upstreamã«é£çµ¡ãæ¥ãªãã¾ã¾èå¼±æ§ãå ¬éããã ruby-devã«Appleãæ¸ããã¨æãããããããè²¼ããã(Appleã§ãªã人éã«ãã£ã¦) ãããã®ã©ã¤ã»ã³ã¹ã䏿ãªã®ã§åãè¾¼ããªã ã©ã¤ã»ã³ã¹ãåãåãããAppleã®çªå£ã䏿ãªã®ã§åãåãããã§ããªã ruby-devãèªãã 人ã¯ã©ã¤ã»ã³ã¹ä¸å®å ¨ãªããããæ¸ããªã èå¼±æ§ã ãã話ã¯éå ¬éã«é²ããã yuguiãããruby-devãèªãã§ãªãåã«æ¸ããããã¨ã«ãã
ãªãªã¼ã¹ãé害æ å ±ãªã©ã®ãµã¼ãã¹ã®ãç¥ãã
ææ°ã®äººæ°ã¨ã³ããªã¼ã®é ä¿¡
å¦çãå®è¡ä¸ã§ã
j次ã®ããã¯ãã¼ã¯
kåã®ããã¯ãã¼ã¯
lãã¨ã§èªã
eã³ã¡ã³ãä¸è¦§ãéã
oãã¼ã¸ãéã
{{#tags}}- {{label}}
{{/tags}}