--------------enig6CA76E6399E8985F732D8D71 Content-Type: text/plain; charset=ISO-2022-JP Content-Transfer-Encoding: quoted-printable Hello all. This is a new release for 1.8.7 series. As Yugui posted earlier, there is a XSS vulnerability in WEBrick HTTP server. Beware that, though we realized this issue only recently, the CVE-2010-0541 has been disclosed for months without notifying us, so public WEBrick servers are already under a real threat of attacks. Many thanks to Hideaki Yamane for letting us know it. Anyway we have a fix for the issue now, and here are those applied for the 1.8.7 branch. All WEBrick users are encouraged to upgrade. URLs: ftp://ftp.ruby-lang.org/pub/ruby/1.8/ruby-1.8.7-p301.tar.gz ftp://ftp.ruby-lang.org/pub/ruby/1.8/ruby-1.8.7-p301.tar.bz2 ftp://ftp.ruby-lang.org/pub/ruby/1.8/ruby-1.8.7-p301.zip Checksum: MD5(ruby-1.8.7-p301.tar.gz)= 2c1a0c3d3d44e77c958e84ead26b1fc9 SHA256(ruby-1.8.7-p301.tar.gz)= c9e3729fee37299348658c50222bc0317ea0a3cdd5abe6af60a5cb7e06f25edb SIZE(ruby-1.8.7-p301.tar.gz)= 4867903 MD5(ruby-1.8.7-p301.tar.bz2)= f461d7672ee99de881f3e9fa5c76fae7 SHA256(ruby-1.8.7-p301.tar.bz2)= 6ddd929722d177240c52e9fafa637dae4d7f8a30825faabb33b1c5391b004029 SIZE(ruby-1.8.7-p301.tar.bz2)= 4183897 MD5(ruby-1.8.7-p301.zip)= 209f447e36207b5989f682008b31e7af SHA256(ruby-1.8.7-p301.zip)= 591c9c6a4210698582fd14f18a715ce19d3a3e4578a7afad2c1e4e126e5cfb0c SIZE(ruby-1.8.7-p301.zip)= 5965403 Thanks, --------------enig6CA76E6399E8985F732D8D71 Content-Type: application/pgp-signature; name="signature.asc" Content-Description: OpenPGP digital signature Content-Disposition: attachment; filename="signature.asc" -----BEGIN PGP SIGNATURE----- Version: GnuPG v1.4.10 (MingW32) Comment: Using GnuPG with Mozilla - http://enigmail.mozdev.org/ iEYEARECAAYFAkxoufYACgkQuTXPUnA5eMJl0wCfUaiP5Np3jJV/ht4sdbnVG9Zu FDYAn18lV/4oI9eLusgs7lTjOJs6njy8 uN -----END PGP SIGNATURE----- --------------enig6CA76E6399E8985F732D8D71--