According to Ruby community web site a denial-of-service vulnerability has been discovered in the bigDecimal standard library. The impact of this hole can allow a hacker to launch a DoS attack by causing BigDecimal to parse an insanely large number, such as: BigDecimal(“9E69999999″).to_s(“F”) Ruby 1.8.6-p368 and all prior versions in addition to 1.8.7-p160 and all [...]



June 13th, 2009
Mourad Ben Lakhoua
Posted in
Tags:



