Go to:
Gentoo Home
Documentation
Forums
Lists
Bugs
Planet
Store
Wiki
Get Gentoo!
Gentoo's Bugzilla – Attachment 61728 Details for
Bug 96784
dev-lang/ruby XMLRPC Server Arbitrary Command Execution (CAN-2005-1992)
Home
|
New
–
[Ex]
|
Browse
|
Search
|
Privacy Policy
|
[?]
|
Reports
|
Requests
|
Help
|
New Account
|
Log In
[x]
|
Forgot Password
Login:
[x]
[patch]
ruby-1.8.2-utils.diff
ruby-1.8.2-utils.diff (text/plain), 979 bytes, created by
Rob Cakebread (RETIRED)
on 2005-06-22 09:39:13 UTC
(
hide
)
Description:
ruby-1.8.2-utils.diff
Filename:
MIME Type:
Creator:
Rob Cakebread (RETIRED)
Created:
2005-06-22 09:39:13 UTC
Size:
979 bytes
patch
obsolete
>--- lib/xmlrpc/utils.rb.org 2003-08-14 10:20:14.000000000 -0700 >+++ lib/xmlrpc/utils.rb 2005-06-19 08:47:31.000000000 -0700 >@@ -6,7 +6,7 @@ > # > # Copyright (C) 2001, 2002, 2003 by Michael Neumann (mneumann@ntecs.de) > # >-# $Id: utils.rb,v 1.2 2003/08/14 17:20:14 matz Exp $ >+# $Id: utils.rb,v 1.4 2005/06/19 15:47:31 mneumann Exp $ > # > > module XMLRPC >@@ -17,13 +17,6 @@ > # key/value pair "___class___" => ClassName > # > module Marshallable >- def __get_instance_variables >- instance_variables.collect {|var| [var[1..-1], eval(var)] } >- end >- >- def __set_instance_variable(key, value) >- eval("@#$1 = value") if key =~ /^([\w_][\w_0-9]*)$/ >- end > end > > >@@ -138,7 +131,7 @@ > > def get_methods(obj, delim=".") > prefix = @prefix + delim >- obj.class.public_instance_methods.collect { |name| >+ obj.class.public_instance_methods(false).collect { |name| > [prefix + name, obj.method(name).to_proc, nil, nil] > } > end
You cannot view the attachment while viewing its details because your browser does not support IFRAMEs.
View the attachment on a separate page
.
View Attachment As Diff
View Attachment As Raw
Actions:
View
|
Diff
Attachments on
bug 96784
:
61727
| 61728