Thanks to visit codestin.com
Credit goes to github.com

Skip to content

Conversation

riseshia
Copy link
Member

@riseshia riseshia commented Feb 10, 2025

πŸ”— #3461

Translates #3489

Actual diff is 062f7b2

@riseshia riseshia marked this pull request as ready for review February 10, 2025 11:30
@riseshia riseshia requested a review from a team as a code owner February 10, 2025 11:30

## μ„ΈλΆ€ λ‚΄μš©

A malicious server can send highly compressed uid-set data which is automatically read by the client's receiver thread. The response parser uses Range#to_a to convert the uid-set data into arrays of integers, with no limitation on the expanded size of the ranges.
Copy link
Member

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

The original is still here πŸ˜…

Copy link
Member Author

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

fixed! 3e7ef7c

@JuanitoFatas JuanitoFatas merged commit 2b6890f into ruby:master Feb 11, 2025
1 check passed
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment
Labels
None yet
Projects
None yet
Development

Successfully merging this pull request may close these issues.

2 participants