<?xml version="1.0" encoding="UTF-8"?>
<?xml-stylesheet type="text/css" href="/stylesheets/rss.css"?>
<rss version="2.0" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:trackback="http://madskills.com/public/xml/rss/module/trackback/">
  <channel>
    <title>Segment7: Upgrade to Rails 1.1.3 Now</title>
    <link>http://blog.segment7.net/articles/2006/06/28/upgrade-to-rails-1-1-3-now</link>
    <language>en-us</language>
    <ttl>40</ttl>
    <description>The Blog</description>
    <item>
      <title>Upgrade to Rails 1.1.3 Now</title>
      <description>DHH &lt;a href="http://weblog.rubyonrails.org/2006/6/27/rails-1-1-3-security-fix-and-minor-fixes"&gt;writes&lt;/a&gt;:

&lt;blockquote&gt;We&amp;rsquo;ve found and fixed a security issue with routing that could cause excess CPU usage in Rails processes when triggered by certain URLs. We strongly encourage anyone running 1.1.x to upgrade to the latest version. It&amp;rsquo;s fully backwards compatible and should serve as a small drop-in fix.&lt;/blockquote&gt;

While certain URLs cause excess CPU usage, other URLs cause Rails to shut down uncleanly or halt (depending upon deployment environment).  You &lt;strong&gt;need&lt;/strong&gt; to upgrade.  (It appears that Rails 1.0 is not vulnerable to this DOS, but I haven't tested.)

While you're upgrading, check your dispatch.fcgi, it should look like &lt;a href="http://dev.rubyonrails.org/browser/trunk/railties/dispatches/dispatch.fcgi"&gt;the current dispatch.fcgi&lt;/a&gt;.  If it doesn't, you need to upgrade it.  There are other DOSs in older versions of dispatch.fcgi.
</description>
      <pubDate>Wed, 28 Jun 2006 12:05:35 -0700</pubDate>
      <guid isPermaLink="false">urn:uuid:2202d76a-83da-443f-a68c-d28eb9f09db0</guid>
      <author>drbrain@segment7.net (Eric Hodel)</author>
      <link>http://blog.segment7.net/articles/2006/06/28/upgrade-to-rails-1-1-3-now</link>
      <category>Rails</category>
    </item>
    <item>
      <title>"Upgrade to Rails 1.1.3 Now" by Eric Hodel</title>
      <description>&lt;p&gt;$ gem install rails&lt;/p&gt;


	&lt;p&gt;Double-check your public/dispatch.fcgi, it should have two lines of code.&lt;/p&gt;</description>
      <pubDate>Sun, 16 Jul 2006 21:37:22 -0700</pubDate>
      <guid isPermaLink="false">urn:uuid:77c7bb44-05e1-4e88-93ae-c0002d2dc2d4</guid>
      <link>http://blog.segment7.net/articles/2006/06/28/upgrade-to-rails-1-1-3-now#comment-283</link>
    </item>
    <item>
      <title>"Upgrade to Rails 1.1.3 Now" by chuck</title>
      <description>&lt;p&gt;Cool.  So, what is the correct process for upgrading to 1.1.3 or 1.1.4?&lt;/p&gt;</description>
      <pubDate>Sun, 16 Jul 2006 21:07:02 -0700</pubDate>
      <guid isPermaLink="false">urn:uuid:6fe933da-5f85-47ee-a50e-55aa59f83873</guid>
      <link>http://blog.segment7.net/articles/2006/06/28/upgrade-to-rails-1-1-3-now#comment-282</link>
    </item>
  </channel>
</rss>
