Upgrade Rails. NOW.

| | Comments (0) | TrackBacks (0)

From Riding Rails:


This is a MANDATORY upgrade for anyone not running on a very recent edge (which isn’t affected by this). If you have a public Rails site, you MUST upgrade to Rails 1.1.5. The security issue is severe and you do not want to be caught unpatched.
[...]
As always, the trick is to do “gem install rails” and then either changing config/environment.rb, if you’re bound to gems, or do “rake rails:freeze:gems” if you’re freezing gems in vendor.

Update: Seems that just versions 1.1.0, 1.1.1, 1.1.2, and 1.1.4 are affected.


Good news: Rails 1.0 and prior is not affected by the latest security breach we’ve experienced. Neither is Rails 1.1.3.

0 TrackBacks

Listed below are links to blogs that reference this entry: Upgrade Rails. NOW..

TrackBack URL for this entry: http://bru.bzaar.net/mt/mt-tr4ckm3.fcgi/704

Leave a comment

Find recent content on the main index or look in the archives to find all content.

Recent Activity

Today

  • Bru tweeted, "congrats to @hrheingold !"
  • Bru tweeted, "that was, sore kara."
  • Bru tweeted, "slre ,a"
  • Bru saved the link Rails Plugin: dynamically_tags
  • Bru tweeted, "@mazphd congrats!"
  • Bru tweeted, "ephemeral javascript time"

Wednesday

  • Bru tweeted, "@waugaman no prob, just send over your email (maybe in a dm)"
  • Bru tweeted, "introduced http://wakeme.at, my experiment with FireEagle, in a long-ish blogpost: http://tinyurl.com/64dq8t"
  • Bru tweeted, "hmm... looks like my Movable Type instance on Dreamhost fell into Internal Server Error hell. :-/"
  • Bru tweeted, "hmm... looks like my Movable Type instance on Dreamhost fell into Internal Server Error hell. :-/"
  • Bru tweeted, "going back to my slicehost playground after what seems a long while"
  • Bru tweeted, "going back to my slicehost playground after what seems a long while"
  • Bru tweeted, "srsly intense day. and only 2 coffee shots. yay!"
  • Bru tweeted, "srsly intense day. and only 2 coffee shots. yay!"
  • Bru tweeted, "retweeting: speak rails? Headshift wants you. DM, send pidgeons, smoke signals, just get in touch."
  • Bru tweeted, "retweeting: speak rails? Headshift wants you. DM, send pidgeons, smoke signals, just get in touch."
  • Bru saved the link Social network popularity around the world
  • Bru tweeted, "feels like a bottleneck"
  • Bru tweeted, "feels like a bottleneck"
  • Bru tweeted, "it's engine war o'clock here in the office"

Pages

Powered by Movable Type 4.2-en