RubyGems DNS flaw now patched after second try

A revised patch has been released for a flaw in the distribution platform for Ruby applications, RubyGems, which could be used to deliver malware to someone trying to download a program.RubyGems lets people search for a “gem,” which is a packaging format for Ruby applications and code libraries. Ruby developers publish a gem when an application is ready.Security researchers from Trustwave found a problem with the platform. When people search for a gem, RubyGems uses a DNS (Domain Name System) SRV record request to find a server hosting a particular gem.The request, however, “does not require that DNS replies come from the same security domain as the original gem source,” according to a writeup, which Trustwave plans to release on its blog on Tuesday.To read this article in full or to leave a comment, please click here Continue reading at 'PC World'

[ PC World | 2015-06-23 00:00:00 UTC ]

Other news stories related to: "RubyGems DNS flaw now patched after second try"


Can digital watermarking protect us from generative AI?

The Biden White House recently enacted its latest executive order designed to establish a guiding framework for generative artificial intelligence development — including content authentication and using digital watermarks to indicate when digital assets made by the Federal government are... Continue reading at Engadget

[ Engadget | 2023-11-30 18:45:42 UTC ]
More news stories like this


RubyGems DNS flaw now patched after second try

A revised patch has been released for a flaw in the distribution platform for Ruby applications, RubyGems, which could be used to deliver malware to someone trying to download a program.RubyGems lets people search for a “gem,” which is a packaging format for Ruby applications and code libraries.... Continue reading at PC World

[ PC World | 2015-06-23 00:00:00 UTC ]
More news stories like this


Over a million Wordpress sites at risk thanks to WP-Slimstat plugin

Wordpress is one of the most popular Web publishing platforms. The vast catalog of plugins is part of what makes Wordpress so powerful, but it can also be the Achilles heel. According to security researchers at Sucuri there are a million-plus Wordpress sites exposed to serious risk, thanks to a... Continue reading at PC World

[ PC World | 2015-02-26 00:00:00 UTC ]
More news stories like this


Report: Snapchat exploits can steal your private info, expose you to spam

A group of security researchers has published a pair Snapchat security exploits, claiming the popular social startup has ignored requests to address them since August -- prior to any Facebook acquisition talk. The Gibson Security team is hoping ... Continue reading at Engadget

[ Engadget | 2013-12-27 00:00:00 UTC ]
More news stories like this