Help assessing Ruby fix to yaml
Moses Mendoza <[email protected]>
| Newsgroups | gmane.text.yaml.general |
|---|---|
| Message-ID | <CA+421WZS2=dzNDwq4EZK5J0iHCNg1hDH-RnP2ALV3iVLJNf1PA@mail.gmail.com> |
Hello, As of version 2.0.0, Ruby carries a vendored copy of yaml in "ext/psych/yaml". Yesterday they went to yaml version 0.1.5. However, an additional fix was introduced to the trunk branch which claims to address a potential integer overflow. The fix is here: https://github.com/ruby/ruby/commit/cb7e80682977f78bfcb2b9e92695e3420b8fd98d. I'm trying to determine if that diff represents a fix to a potential security vulnerability, but I'm afraid my familiarity with the yaml source code is not very good. Does this appear to be a security vulnerability? I'm trying to determine if I need to pull this patch in. Thank you for your help. -- Moses Mendoza Puppet Labs ------------------------------------------------------------------------------ Managing the Performance of Cloud-Based Applications Take advantage of what the Cloud has to offer - Avoid Common Pitfalls. Read the Whitepaper. http://pubads.g.doubleclick.net/gampad/clk?id=121051231&iu=/4140/ostg.clktrk