Re: [Catalyst] [Fwd: [rt-users] Security vulnerability in RT 3.0 and up]

2008-07-20 Thread Dave Rolsky
On Sun, 20 Jul 2008, Matt S Trout wrote: On Mon, Jun 23, 2008 at 01:17:15PM -0400, Lance A. Brown wrote: H. Is this something Catalyst needs to worry about? StackTrace only activates for Catlyst in debug mode. But if you're writing Mason views, Mason uses Devel::StackTrace internally

Re: [Catalyst] [Fwd: [rt-users] Security vulnerability in RT 3.0 and up]

2008-07-19 Thread Matt S Trout
On Mon, Jun 23, 2008 at 01:17:15PM -0400, Lance A. Brown wrote: > H. Is this something Catalyst needs to worry about? StackTrace only activates for Catlyst in debug mode. If you're deploying your app publically in debug mode, you have more than this to worry about (like exceptions showing y

Re: [Catalyst] [Fwd: [rt-users] Security vulnerability in RT 3.0 and up]

2008-06-24 Thread Dave Rolsky
On Mon, 23 Jun 2008, Lance A. Brown wrote: H. Is this something Catalyst needs to worry about? The case to tickle this particular bug is that you need to pass bad UTF8 to a sub that's in the call chain and then generate a Devel::StackTrace object and then try to stringify that object.

[Catalyst] [Fwd: [rt-users] Security vulnerability in RT 3.0 and up]

2008-06-23 Thread Lance A. Brown
H. Is this something Catalyst needs to worry about? --[Lance] -- GPG Fingerprint: 409B A409 A38D 92BF 15D9 6EEE 9A82 F2AC 69AC 07B9 CACert.org Assurer --- Begin Message --- All versions of RT from 3.0.0 to 3.6.6 (including some, but not all RT 3.7 development releases) are vulnerable to