<?xml version="1.0" encoding="UTF-8"?><rss version="2.0"
	xmlns:content="http://purl.org/rss/1.0/modules/content/"
	xmlns:dc="http://purl.org/dc/elements/1.1/"
	xmlns:atom="http://www.w3.org/2005/Atom"
	xmlns:sy="http://purl.org/rss/1.0/modules/syndication/"
		>
<channel>
	<title>Comments on: Ruby Enterprise Edition 1.8.6-20090610 released: fixes BigDecimal DoS vulnerability</title>
	<atom:link href="http://blog.phusion.nl/2009/06/10/ruby-enterprise-edition-186-20090610-released-fixes-bigdecimal-dos-vulnerability/feed/" rel="self" type="application/rss+xml" />
	<link>http://blog.phusion.nl/2009/06/10/ruby-enterprise-edition-186-20090610-released-fixes-bigdecimal-dos-vulnerability/</link>
	<description></description>
	<lastBuildDate>Fri, 03 Feb 2012 23:02:15 +0000</lastBuildDate>
	<sy:updatePeriod>hourly</sy:updatePeriod>
	<sy:updateFrequency>1</sy:updateFrequency>
	<generator>http://wordpress.org/?v=3.3.1</generator>
	<item>
		<title>By: RUSSIAN BLACKEDITION &#187; Blog Archive &#187; Ruby / PODCAST Ruby NoName Podcast #12</title>
		<link>http://blog.phusion.nl/2009/06/10/ruby-enterprise-edition-186-20090610-released-fixes-bigdecimal-dos-vulnerability/comment-page-1/#comment-7311</link>
		<dc:creator>RUSSIAN BLACKEDITION &#187; Blog Archive &#187; Ruby / PODCAST Ruby NoName Podcast #12</dc:creator>
		<pubDate>Tue, 23 Jun 2009 01:40:43 +0000</pubDate>
		<guid isPermaLink="false">http://blog.phusion.nl/?p=270#comment-7311</guid>
		<description>[...] RubyEE fix for DoS [...]</description>
		<content:encoded><![CDATA[<p>[...] RubyEE fix for DoS [...]</p>
]]></content:encoded>
	</item>
	<item>
		<title>By: Crónica de una vida - Aviso a navegantes &#8211; Actualizar Ruby y Ruby enterprise -DoS</title>
		<link>http://blog.phusion.nl/2009/06/10/ruby-enterprise-edition-186-20090610-released-fixes-bigdecimal-dos-vulnerability/comment-page-1/#comment-7163</link>
		<dc:creator>Crónica de una vida - Aviso a navegantes &#8211; Actualizar Ruby y Ruby enterprise -DoS</dc:creator>
		<pubDate>Tue, 16 Jun 2009 21:09:25 +0000</pubDate>
		<guid isPermaLink="false">http://blog.phusion.nl/?p=270#comment-7163</guid>
		<description>[...] http://blog.phusion.nl/2009/06/10/ruby-enterprise-edition-186-20090610-released-fixes-bigdecimal-dos... [...]</description>
		<content:encoded><![CDATA[<p>[...] <a href="http://blog.phusion.nl/2009/06/10/ruby-enterprise-edition-186-20090610-released-fixes-bigdecimal-dos.." rel="nofollow">http://blog.phusion.nl/2009/06/10/ruby-enterprise-edition-186-20090610-released-fixes-bigdecimal-dos..</a>. [...]</p>
]]></content:encoded>
	</item>
	<item>
		<title>By: hongli</title>
		<link>http://blog.phusion.nl/2009/06/10/ruby-enterprise-edition-186-20090610-released-fixes-bigdecimal-dos-vulnerability/comment-page-1/#comment-7081</link>
		<dc:creator>hongli</dc:creator>
		<pubDate>Fri, 12 Jun 2009 18:51:08 +0000</pubDate>
		<guid isPermaLink="false">http://blog.phusion.nl/?p=270#comment-7081</guid>
		<description>No. All REE releases so far are binary compatible so you don&#039;t have to reinstall your gems if you are upgrading from an older version of REE.</description>
		<content:encoded><![CDATA[<p>No. All REE releases so far are binary compatible so you don&#8217;t have to reinstall your gems if you are upgrading from an older version of REE.</p>
]]></content:encoded>
	</item>
	<item>
		<title>By: matte</title>
		<link>http://blog.phusion.nl/2009/06/10/ruby-enterprise-edition-186-20090610-released-fixes-bigdecimal-dos-vulnerability/comment-page-1/#comment-7079</link>
		<dc:creator>matte</dc:creator>
		<pubDate>Fri, 12 Jun 2009 18:36:12 +0000</pubDate>
		<guid isPermaLink="false">http://blog.phusion.nl/?p=270#comment-7079</guid>
		<description>Is it necessary to reinstall the Apache Passenger module after the upgrade?  I&#039;m upgrading from 20090421.

(e)</description>
		<content:encoded><![CDATA[<p>Is it necessary to reinstall the Apache Passenger module after the upgrade?  I&#8217;m upgrading from 20090421.</p>
<p>(e)</p>
]]></content:encoded>
	</item>
	<item>
		<title>By: Michael</title>
		<link>http://blog.phusion.nl/2009/06/10/ruby-enterprise-edition-186-20090610-released-fixes-bigdecimal-dos-vulnerability/comment-page-1/#comment-7026</link>
		<dc:creator>Michael</dc:creator>
		<pubDate>Thu, 11 Jun 2009 08:32:47 +0000</pubDate>
		<guid isPermaLink="false">http://blog.phusion.nl/?p=270#comment-7026</guid>
		<description>Thanks hongli for your quick reply!

And by the way, as i&#039;m already commenting, thanks for the great work on passenger and ree!

Cheers,
Michael.</description>
		<content:encoded><![CDATA[<p>Thanks hongli for your quick reply!</p>
<p>And by the way, as i&#8217;m already commenting, thanks for the great work on passenger and ree!</p>
<p>Cheers,<br />
Michael.</p>
]]></content:encoded>
	</item>
	<item>
		<title>By: hongli</title>
		<link>http://blog.phusion.nl/2009/06/10/ruby-enterprise-edition-186-20090610-released-fixes-bigdecimal-dos-vulnerability/comment-page-1/#comment-7025</link>
		<dc:creator>hongli</dc:creator>
		<pubDate>Thu, 11 Jun 2009 08:29:52 +0000</pubDate>
		<guid isPermaLink="false">http://blog.phusion.nl/?p=270#comment-7025</guid>
		<description>Michael: REE is based on 1.8.6, so it doesn&#039;t break BigDecimal#to_f.</description>
		<content:encoded><![CDATA[<p>Michael: REE is based on 1.8.6, so it doesn&#8217;t break BigDecimal#to_f.</p>
]]></content:encoded>
	</item>
	<item>
		<title>By: Michael</title>
		<link>http://blog.phusion.nl/2009/06/10/ruby-enterprise-edition-186-20090610-released-fixes-bigdecimal-dos-vulnerability/comment-page-1/#comment-7024</link>
		<dc:creator>Michael</dc:creator>
		<pubDate>Thu, 11 Jun 2009 08:24:59 +0000</pubDate>
		<guid isPermaLink="false">http://blog.phusion.nl/?p=270#comment-7024</guid>
		<description>Can anybody confirm that REE doesn&#039;t break like described here:

http://www.getharvest.com/blog/2009/06/ruby-denial-of-service-patch-breaks-bigdecimal-to_f-method/

Thanks!</description>
		<content:encoded><![CDATA[<p>Can anybody confirm that REE doesn&#8217;t break like described here:</p>
<p><a href="http://www.getharvest.com/blog/2009/06/ruby-denial-of-service-patch-breaks-bigdecimal-to_f-method/" rel="nofollow">http://www.getharvest.com/blog/2009/06/ruby-denial-of-service-patch-breaks-bigdecimal-to_f-method/</a></p>
<p>Thanks!</p>
]]></content:encoded>
	</item>
	<item>
		<title>By: Shell Script to Upgrade Ruby Enterprise Edition while Maintaining Directory Naming Sanity &#171; SmartLogic Solutions Blog</title>
		<link>http://blog.phusion.nl/2009/06/10/ruby-enterprise-edition-186-20090610-released-fixes-bigdecimal-dos-vulnerability/comment-page-1/#comment-7020</link>
		<dc:creator>Shell Script to Upgrade Ruby Enterprise Edition while Maintaining Directory Naming Sanity &#171; SmartLogic Solutions Blog</dc:creator>
		<pubDate>Thu, 11 Jun 2009 01:24:36 +0000</pubDate>
		<guid isPermaLink="false">http://blog.phusion.nl/?p=270#comment-7020</guid>
		<description>[...] already aware, a denial of service (DoS) vulnerability in Ruby&#8217;s BigDecimal library was uncovered, fixed and reported on June 9, 2009. Patching options [...]</description>
		<content:encoded><![CDATA[<p>[...] already aware, a denial of service (DoS) vulnerability in Ruby&#8217;s BigDecimal library was uncovered, fixed and reported on June 9, 2009. Patching options [...]</p>
]]></content:encoded>
	</item>
	<item>
		<title>By: Roderick van Domburg</title>
		<link>http://blog.phusion.nl/2009/06/10/ruby-enterprise-edition-186-20090610-released-fixes-bigdecimal-dos-vulnerability/comment-page-1/#comment-7013</link>
		<dc:creator>Roderick van Domburg</dc:creator>
		<pubDate>Wed, 10 Jun 2009 21:20:52 +0000</pubDate>
		<guid isPermaLink="false">http://blog.phusion.nl/?p=270#comment-7013</guid>
		<description>Thanks for the swift response.</description>
		<content:encoded><![CDATA[<p>Thanks for the swift response.</p>
]]></content:encoded>
	</item>
	<item>
		<title>By: Tom Copeland</title>
		<link>http://blog.phusion.nl/2009/06/10/ruby-enterprise-edition-186-20090610-released-fixes-bigdecimal-dos-vulnerability/comment-page-1/#comment-7009</link>
		<dc:creator>Tom Copeland</dc:creator>
		<pubDate>Wed, 10 Jun 2009 16:20:46 +0000</pubDate>
		<guid isPermaLink="false">http://blog.phusion.nl/?p=270#comment-7009</guid>
		<description>Sorry about that, back online now.</description>
		<content:encoded><![CDATA[<p>Sorry about that, back online now.</p>
]]></content:encoded>
	</item>
</channel>
</rss>

