The Ruby developers have released an update to the 1.9.3 series of their open source programming language, fixing a denial-of-service vulnerability. Ruby 1.9.3 patch level 327, labelled 1.9.3-p327, corrects a hash-flooding issue that could be exploited by an attacker to cause a high CPU load that can result in a denial-of-service. . The problem can be caused by an error when parsing specially crafted sequences of strings. The link for this article located at H Security is no longer available. . The Ruby 1.9.3 revision resolves the hash collision vulnerability that could lead to denial-of-service attacks. Ensure your installation is up to date for enhanced security.. Ruby Update, Denial Of Service, Hash Flooding, Software Patch, Open Source. . LinuxSecurity.com Team
The Ruby developers had a near miss with a crypto disaster when an "awful bug" crept into the language's source code development tree. A simple programming error made the library generate RSA keys that caused the encryption mechanism to produce clear text. . Luckily, the error was caught before it made it to any release version of Ruby, but it provides a good example of how a simple error can have potentially far-reaching effects. The RSA asymmetric encryption technique differentiates between secret and public keys. The public key consist of a modulus n and an exponent e. The plain text, m, is encrypted according to the mathematical formula The link for this article located at H Security is no longer available. . An incident during the advancement of Python highlights significant dangers presented by blockchain flaws that may result in decryption errors.. Ruby Security Breach, RSA Encryption Issues, Crypto Development Risks. . LinuxSecurity.com Team
Get the latest Linux and open source security news straight to your inbox.