<?xml version="1.0" encoding="UTF-8"?>
<rss version="2.0" xmlns:dc="http://purl.org/dc/elements/1.1/">
  <channel>
    <title>Ruby News</title>
    <link>http://www.ruby-lang.org/en/feeds/news.rss/</link>
 <language>en-us</language>
    <ttl>40</ttl>
    <description>The latest news from Ruby-Lang.org.</description>
    
    
        <item>
     <title>Ruby 1.8.6 released!</title>
          <description>&lt;p&gt;Ruby 1.8.6 has been released (see the &lt;a href=&quot;http://blade.nagaokaut.ac.jp/cgi-bin/scat.rb/ruby/ruby-list/43267&quot;&gt;announcement on Ruby-Talk&lt;/a&gt;). The source is available in three formats:&lt;/p&gt;

&lt;dl&gt;
  &lt;dt&gt;&lt;a href=&quot;ftp://ftp.ruby-lang.org/pub/ruby/1.8/ruby-1.8.6.tar.bz2&quot;&gt;&lt;strong&gt;ruby-1.8.6.tar.bz2&lt;/strong&gt;&lt;/a&gt; &lt;small style=&quot;font-weight:normal&quot;&gt;(3.8 MB)&lt;/small&gt;&lt;/dt&gt;
  &lt;dd&gt;
&lt;pre&gt;
md5: e558a0e00ae318d43bf6ff9af452bad2
sha256: 0fc6ad0b31d8ec3997db2a56a2ac1c235283a3607abb876300fc711b3f8e3dd7
&lt;/pre&gt;
 &lt;/dd&gt;

  &lt;dt&gt;&lt;a href=&quot;ftp://ftp.ruby-lang.org/pub/ruby/1.8/ruby-1.8.6.tar.gz&quot;&gt;&lt;strong&gt;ruby-1.8.6.tar.gz&lt;/strong&gt;&lt;/a&gt; &lt;small style=&quot;font-weight:normal&quot;&gt;(4.4 MB)&lt;/small&gt;&lt;/dt&gt;
  &lt;dd&gt;
&lt;pre&gt;
md5: 23d2494aa94e7ae1ecbbb8c5e1507683
sha256: 3ef37fb961d04471a1aef2c8079d6fab09932e3281d79859d5cd5d426bde0868
&lt;/pre&gt;
 &lt;/dd&gt;

  &lt;dt&gt;&lt;a href=&quot;ftp://ftp.ruby-lang.org/pub/ruby/1.8/ruby-1.8.6.zip&quot;&gt;&lt;strong&gt;ruby-1.8.6.zip&lt;/strong&gt;&lt;/a&gt; &lt;small style=&quot;font-weight:normal&quot;&gt;(5.3 MB)&lt;/small&gt;&lt;/dt&gt;
  &lt;dd&gt;
&lt;pre&gt;
md5: 5f4b82cec8f437634e05a3ce9bb3ca67
sha256: c4b011d66b3f7e3bddbdf61a7404120d5ac80c6b742ad08e7e75b6d14ee56e76
&lt;/pre&gt;
 &lt;/dd&gt;
&lt;/ul&gt;
 &lt;p&gt;For a brief list of user visible changes and a full list of all
changes since 1.8.5, see the bundled files &lt;a href=&quot;http://svn.ruby-lang.org/repos/ruby/tags/v1_8_6/NEWS&quot;&gt;&lt;span class=&quot;caps&quot;&gt;NEWS&lt;/span&gt;&lt;/a&gt; and &lt;a href=&quot;http://svn.ruby-lang.org/repos/ruby/tags/v1_8_6/ChangeLog&quot;&gt;ChangeLog&lt;/a&gt;.&lt;/p&gt;


	&lt;p&gt;After this announcement, we will start the development for 1.8.7 as
well as maintaining the &amp;#8220;ruby_1_8_6&amp;#8221; branch on which only critical
bugs and security vulnerabilities found in the 1.8.6 release are
fixed, and patch releases will follow on appropriate and timely
occasions. Please check them out after upgrading Ruby to 1.8.6.&lt;/p&gt;</description>
 <pubDate>Mon, 12 Mar 2007 21:52:53 GMT</pubDate>
          <guid>http://www.ruby-lang.org/en/news/2007/03/12/ruby-1-8-6-released/</guid>
 <link>http://www.ruby-lang.org/en/news/2007/03/12/ruby-1-8-6-released/</link>
 </item>
    
        <item>
          <title>CVS services will be permanently unavailable</title>
          <description>&lt;p&gt;CVS services (including CVSup and CVSweb) will be permanently
unavailable on Fri Mar 16 03:00 UTC 2007.  The source code
repositry has been &lt;a href=&quot;/en/news/2006/12/22/cvs-repository-moved-to-svn/&quot;&gt;moved to SVN&lt;/a&gt;.&lt;/p&gt;&lt;p&gt;If you require the CVS repositry, please get it by CVSup till
that day.&lt;/p&gt; </description>
          <pubDate>Thu, 01 Mar 2007 00:46:32 GMT</pubDate>
          <guid>http://www.ruby-lang.org/en/news/2007/03/01/cvs-services-will-be-permanently-unavailable/</guid>
 <link>http://www.ruby-lang.org/en/news/2007/03/01/cvs-services-will-be-permanently-unavailable/</link>
 </item>
    
        <item>
          <title>IP Address Change</title>
          <description>&lt;p&gt;The IP address of the server will be changed on Thu Feb 22 03:00:00 UTC 2007, and WWW/FTP/ML and Anonymous CVS services will be stopped in a few minutes.&lt;/p&gt;

&lt;p&gt;Sorry for inconvenience.&lt;/p&gt; </description>
          <pubDate>Wed, 21 Feb 2007 10:12:21 GMT</pubDate>
          <guid>http://www.ruby-lang.org/en/news/2007/02/21/ip-address-change/</guid>
  <link>http://www.ruby-lang.org/en/news/2007/02/21/ip-address-change/</link>
  </item>
    
        <item>
          <title>MountainWest Speaker List Posted</title>
          <description>&lt;p&gt;The list of speakers and topics for MountainWest RubyConf has &lt;a href=&quot;http://mtnwestruby.org/speakers&quot;&gt;gone up.&lt;/a&gt;&lt;/p&gt;


	&lt;p&gt;There&amp;#8217;s also a nice &lt;a href=&quot;http://mtnwestruby.conferencemeetup.com/people&quot;&gt;social site&lt;/a&gt; for the conference as well.&lt;/p&gt; </description>
          <pubDate>Fri, 26 Jan 2007 08:25:39 GMT</pubDate>
          <guid>http://www.ruby-lang.org/en/news/2007/01/26/mountainwest-speaker-list-posted/</guid>
 <link>http://www.ruby-lang.org/en/news/2007/01/26/mountainwest-speaker-list-posted/</link>
 </item>
    
        <item>
          <title>MountainWest RubyConf 2007 Registration Now Open</title>
          <description>&lt;p&gt;Registration for the upcoming &lt;a href=&quot;http://mtnwestruby.org&quot;&gt;MountainWest RubyConf&lt;/a&gt;  is open.&lt;/p&gt;


	&lt;p&gt;This regional Ruby conference will be in Salt Lake City, Utah, &lt;span class=&quot;caps&quot;&gt;USA&lt;/span&gt;, on March 16 and 17, 2007.&lt;/p&gt;


	&lt;p&gt;$50 gets you a seat and a T-shirt.  More details are forthcoming, but, trust me, this will be good.&lt;/p&gt; </description>
  <pubDate>Wed, 24 Jan 2007 23:14:46 GMT</pubDate>
          <guid>http://www.ruby-lang.org/en/news/2007/01/24/mountainwest-rubyconf-2007-registration-now-open/</guid>
 <link>http://www.ruby-lang.org/en/news/2007/01/24/mountainwest-rubyconf-2007-registration-now-open/</link>
 </item>
    
        <item>
          <title>Ruby on Rails Bootcamp in Georgia</title>
          <description>&lt;p&gt;Big Nerd Ranch, Inc. is offering their Ruby on Rails Bootcamp classes in a retreat setting outside Atlanta, GA the week of February 12th-16th. For more information you can find the press release at &lt;a href=&quot;http://bignerdranch.com/news/2006-10-11.shtml&quot;&gt;http://bignerdranch.com/news/2006-10-11.shtml&lt;/a&gt;.&lt;/p&gt; </description>
          <pubDate>Wed, 27 Dec 2006 21:35:10 GMT</pubDate>
 <guid>http://www.ruby-lang.org/en/news/2006/12/27/ruby-on-rails-bootcamp-in-georgia/</guid>
 <link>http://www.ruby-lang.org/en/news/2006/12/27/ruby-on-rails-bootcamp-in-georgia/</link>
 </item>
    
        <item>
          <title>CVS Repository moved to SVN</title>
          <description>&lt;p&gt;We have moved the source code repository to &lt;a href=&quot;http://svn.ruby-lang.org/repos/ruby/&quot;&gt;http://svn.ruby-lang.org/repos/ruby/&lt;/a&gt;.
You can checkout it using the svn command, or you can also browse it by &lt;a href=&quot;http://svn.ruby-lang.org/cgi-bin/viewvc.cgi?root=ruby&quot;&gt;ViewVC&lt;/a&gt;.&lt;/p&gt;&lt;p&gt;The new machine for svn.ruby-lang.org is provided by &lt;a href=&quot;http://www.sun.com&quot;&gt;Sun Microsystems&lt;/a&gt;.
We are using &lt;a href=&quot;http://www.sun.com/software/solaris/&quot;&gt;Solaris 10&lt;/a&gt; on the new machine, and it works pretty well.&lt;/p&gt; </description>
          <pubDate>Fri, 22 Dec 2006 10:59:26 GMT</pubDate>
 <guid>http://www.ruby-lang.org/en/news/2006/12/22/cvs-repository-moved-to-svn/</guid>
 <link>http://www.ruby-lang.org/en/news/2006/12/22/cvs-repository-moved-to-svn/</link>
 </item>
    
        <item>
          <title>Ruby on Rails Bootcamp in Germany</title>
          <description>&lt;p&gt;Big Nerd Ranch Europe is offering their Ruby on Rails Bootcamp classes in Kloster Eberbach, Germany (near Frankfurt) the week of March 26th-30th.  For more information you can find the press release at &lt;a href=&quot;http://www.bignerdranch.com/news/2006-12-20.shtml&quot;&gt;http://www.bignerdranch.com/news/2006-12-20.shtml&lt;/a&gt;.&lt;/p&gt; </description>
          <pubDate>Wed, 20 Dec 2006 22:30:36 GMT</pubDate>
 <guid>http://www.ruby-lang.org/en/news/2006/12/20/ruby-on-rails-bootcamp-in-germany/</guid>
 <link>http://www.ruby-lang.org/en/news/2006/12/20/ruby-on-rails-bootcamp-in-germany/</link>
 </item>
    
        <item>
          <title>Another DoS Vulnerability in CGI Library</title>
          <description>&lt;p&gt;Another vulnerability has been discovered in the CGI library (cgi.rb)
that ships with Ruby which could be used by a malicious user to
create a denial of service attack (DoS).&lt;/p&gt;&lt;p&gt;This vulnerability is open to the public as
&lt;a href=&quot;http://jvn.jp/jp/JVN%2384798830/index.html&quot;&gt;JVN#84798830&lt;/a&gt;.&lt;/p&gt;&lt;p&gt;Please note that the previous patch
(&lt;a href=&quot;http://ftp.ruby-lang.org/pub/ruby/1.8/ruby-1.8.5-cgi-dos-1.patch&quot;&gt;&amp;lt;URL:http://ftp.ruby-lang.org/pub/ruby/1.8/ruby-1.8.5-cgi-dos-1.patch&amp;gt;&lt;/a&gt;)
does not fix this problem.&lt;/p&gt; &lt;h4&gt;&lt;a name=&quot;label-0&quot; id=&quot;label-0&quot;&gt;Impact&lt;/a&gt;&lt;/h4&gt;&lt;!-- RDLabel: &quot;Impact&quot; --&gt;&lt;p&gt;A specific HTTP request for any web application using cgi.rb
causes CPU consumption on the machine on which the web application
is running.
Many such requests result in a denial of service.&lt;/p&gt;&lt;h4&gt;&lt;a name=&quot;label-1&quot; id=&quot;label-1&quot;&gt;Vulnerable versions&lt;/a&gt;&lt;/h4&gt;&lt;!-- RDLabel: &quot;Vulnerable versions&quot; --&gt;&lt;dl&gt;
&lt;dt&gt;&lt;a name=&quot;label-2&quot; id=&quot;label-2&quot;&gt;1.8 series&lt;/a&gt;&lt;/dt&gt;&lt;!-- RDLabel: &quot;1.8 series&quot; --&gt;
&lt;dd&gt;
1.8.5 and all prior versions
&lt;/dd&gt;
&lt;dt&gt;&lt;a name=&quot;label-3&quot; id=&quot;label-3&quot;&gt;Development version (1.9 series)&lt;/a&gt;&lt;/dt&gt;&lt;!-- RDLabel: &quot;Development version (1.9 series)&quot; --&gt;
&lt;dd&gt;
All versions before 2006-12-04
&lt;/dd&gt;
&lt;/dl&gt;&lt;h4&gt;&lt;a name=&quot;label-4&quot; id=&quot;label-4&quot;&gt;Solution&lt;/a&gt;&lt;/h4&gt;&lt;!-- RDLabel: &quot;Solution&quot; --&gt;&lt;dl&gt;
&lt;dt&gt;&lt;a name=&quot;label-5&quot; id=&quot;label-5&quot;&gt;1.8 series&lt;/a&gt;&lt;/dt&gt;&lt;!-- RDLabel: &quot;1.8 series&quot; --&gt;
&lt;dd&gt;
&lt;p&gt;Please upgrade to 1.8.5-p2.&lt;/p&gt;
&lt;p&gt;&lt;a href=&quot;http://ftp.ruby-lang.org/pub/ruby/1.8/ruby-1.8.5-p2.tar.gz&quot;&gt;&amp;lt;URL:http://ftp.ruby-lang.org/pub/ruby/1.8/ruby-1.8.5-p2.tar.gz&amp;gt;&lt;/a&gt;
(4519151 bytes, md5sum: a3517a224716f79b14196adda3e88057)&lt;/p&gt;
&lt;p&gt;Please note that a package that corrects this weakness may already be available through your package management software. &lt;/p&gt;
&lt;/dd&gt;
&lt;dt&gt;&lt;a name=&quot;label-6&quot; id=&quot;label-6&quot;&gt;Development version (1.9 series)&lt;/a&gt;&lt;/dt&gt;&lt;!-- RDLabel: &quot;Development version (1.9 series)&quot; --&gt;
&lt;dd&gt;
Please update your Ruby to a version after 2006-12-04.
&lt;/dd&gt;
&lt;/dl&gt;</description>
          <pubDate>Mon, 04 Dec 2006 02:00:40 GMT</pubDate>
          <guid>http://www.ruby-lang.org/en/news/2006/12/04/another-dos-vulnerability-in-cgi-library/</guid>
 <link>http://www.ruby-lang.org/en/news/2006/12/04/another-dos-vulnerability-in-cgi-library/</link>
 </item>
    
        <item>
          <title>DoS Vulnerability in CGI Library</title>
          <description>&lt;p&gt;A vulnerability has been discovered in the &lt;span class=&quot;caps&quot;&gt;CGI&lt;/span&gt; library (cgi.rb) that ships with Ruby which could be used by a malicious user to create a denial of service attack (DoS). The problem is triggered by sending the library an &lt;span class=&quot;caps&quot;&gt;HTTP&lt;/span&gt; request that uses multipart &lt;span class=&quot;caps&quot;&gt;MIME&lt;/span&gt; encoding and has an invalid boundary specifier that begins with &amp;#8220;-&amp;#8221; instead of &amp;#8220;--&amp;#8221;. Once triggered it will exhaust all available memory resources effectively creating a DoS condition.&lt;/p&gt;


	&lt;p&gt;&lt;strong&gt;Ruby 1.8.5 and all prior versions are vulnerable.&lt;/strong&gt; This vulnerability is open to the public as &lt;a href=&quot;http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2006-5467&quot;&gt;&lt;span class=&quot;caps&quot;&gt;CVE&lt;/span&gt;-2006-5467&lt;/a&gt;.&lt;/p&gt; &lt;h3&gt;Vulnerable Versions&lt;/h3&gt;


&lt;dl&gt;
&lt;dt&gt;1.8 series&lt;/dt&gt;
&lt;dd&gt;1.8.5 and all prior versions&lt;/dd&gt;

&lt;dt&gt;Development version (1.9 series)&lt;/dt&gt;
&lt;dd&gt;All versions before 2006-09-23&lt;/dd&gt;
&lt;/dl&gt;

	&lt;h3&gt;Solution&lt;/h3&gt;


&lt;dl&gt;
&lt;dt&gt;1.8 series&lt;/dt&gt;
&lt;dd&gt;
Please apply the patch after you update to Ruby 1.8.5:

&lt;ul&gt;&lt;li&gt;&lt;a href=&quot;http://ftp.ruby-lang.org/pub/ruby/1.8/ruby-1.8.5-cgi-dos-1.patch&quot;&gt;&lt;span class=&quot;caps&quot;&gt;CGI&lt;/span&gt; DoS Patch&lt;/a&gt; (367 bytes; md5sum: 9d25f59d1c33a0b215f6c25260dcb536)&lt;/li&gt;&lt;/ul&gt;

Please note that a package that corrects this weakness may already be available through your package management software.
&lt;/dd&gt;

&lt;dt&gt;Development version (1.9 series)&lt;/dt&gt;
&lt;dd&gt;Please update your Ruby to a version after September 23, 2006.&lt;/dd&gt;
&lt;/dl&gt;

	&lt;h3&gt;References&lt;/h3&gt;


	&lt;ul&gt;
	&lt;li&gt;&lt;a href=&quot;http://rubyforge.org/pipermail/mongrel-users/2006-October/001946.html&quot; lang=&quot;Mongrel&quot;&gt; [SEC] Mongrel Temporary Fix For cgi.rb 99% &lt;span class=&quot;caps&quot;&gt;CPU&lt;/span&gt; DoS Attack&lt;/a&gt;&lt;/li&gt;
	&lt;/ul&gt;</description>
          <pubDate>Fri, 03 Nov 2006 16:35:33 GMT</pubDate>
          <guid>http://www.ruby-lang.org/en/news/2006/11/03/CVE-2006-5467/</guid>
      <link>http://www.ruby-lang.org/en/news/2006/11/03/CVE-2006-5467/</link>
      </item>
    
    
  </channel>
</rss>