Category: Open Source
Arguments for making the private method work on constants
CVE-2024-43398: DoS vulnerability in REXML
There is a DoS vulnerability in REXML gem. This vulnerability has been assigned the CVE identifier CVE-2024-43398. We strongly recommend upgrading the REXML gem.
Details
When parsing an XML that has many deep elements that have same local name attributes.
It’s only affected with the tree parser API. If you’re using REXML::Document.new
to parse an XML, you may be affected.
Please update REXML gem to version 3.3.6 or later.
Affected versions
- REXML gem 3.3.5 or prior
Credits
Thanks to l33thaxor for discovering this issue.
History
- Originally published at 2024-08-22 03:00:00 (UTC)
Posted by kou on 22 Aug 2024
parallel @ Savannah: GNU Parallel 20240822 (‘Southport’) released
GNU Parallel 20240822 (‘Southport’) has been released. It is available for download at: lbry://@GnuParallel:4
Quote of the month:
honestly the coolest software i’ve ever seen gotta be gnu parallel or
ffmpeg, nothing like them
— @scootykins scoot
New in this release:
- –match Match input source with regexp to set replacement fields.
- {:%fmt} Use printf formatting of replacement strings.
- Bug fixes and man page updates.
News about GNU Parallel:
- Powerful GNU parallel, more than a loop https://www.linkedin.com/pulse/powerful-gnu-parallel-more-than-loop-zhenguo-zhang-18dxc
- How To Increase File Transfer Speed Using Parallel Rsync? https://contentbase.com/blog/increase-file-transfer-speed-parallel-rsync/
- Converting WebP Images to PNG Using parallel and dwebp https://bytefreaks.net/2024/07/27
- Turbocharging the Box CLI with GNU Parallel https://medium.com/box-developer-blog/turbocharging-the-box-cli-with-gnu-parallel-ee44c48811c0
GNU Parallel – For people who live life in the parallel lane.
If you like GNU Parallel record a video testimonial: Say who you are, what you use GNU Parallel for, how it helps you, and what you like most about it. Include a command that uses GNU Parallel if you feel like it.
About GNU Parallel
GNU Parallel is a shell tool for executing jobs in parallel using one or more computers. A job can be a single command or a small script that has to be run for each of the lines in the input. The typical input is a list of files, a list of hosts, a list of users, a list of URLs, or a list of tables. A job can also be a command that reads from a pipe. GNU Parallel can then split the input and pipe it into commands in parallel.
If you use xargs and tee today you will find GNU Parallel very easy to use as GNU Parallel is written to have the same options as xargs. If you write loops in shell, you will find GNU Parallel may be able to replace most of the loops and make them run faster by running several jobs in parallel. GNU Parallel can even replace nested loops.
GNU Parallel makes sure output from the commands is the same output as you would get had you run the commands sequentially. This makes it possible to use output from GNU Parallel as input for other programs.
For example you can run this to convert all jpeg files into png and gif files and have a progress bar:
parallel –bar convert {1} {1.}.{2} ::: *.jpg ::: png gif
Or you can generate big, medium, and small thumbnails of all jpeg files in sub dirs:
find . -name ‘*.jpg’ |
parallel convert -geometry {2} {1} {1//}/thumb{2}_{1/} :::: – ::: 50 100 200
You can find more about GNU Parallel at: http://www.gnu.org/s/parallel/
You can install GNU Parallel in just 10 seconds with:
$ (wget -O – pi.dk/3 || lynx -source pi.dk/3 || curl pi.dk/3/ ||
fetch -o – http://pi.dk/3 ) > install.sh
$ sha1sum install.sh | grep 883c667e01eed62f975ad28b6d50e22a
12345678 883c667e 01eed62f 975ad28b 6d50e22a
$ md5sum install.sh | grep cc21b4c943fd03e93ae1ae49e28573c0
cc21b4c9 43fd03e9 3ae1ae49 e28573c0
$ sha512sum install.sh | grep ec113b49a54e705f86d51e784ebced224fdff3f52
79945d9d 250b42a4 2067bb00 99da012e c113b49a 54e705f8 6d51e784 ebced224
fdff3f52 ca588d64 e75f6033 61bd543f d631f592 2f87ceb2 ab034149 6df84a35
$ bash install.sh
Watch the intro video on http://www.youtube.com/playlist?list=PL284C9FF2488BC6D1
Walk through the tutorial (man parallel_tutorial). Your command line will love you for it.
When using programs that use GNU Parallel to process data for publication please cite:
O. Tange (2018): GNU Parallel 2018, March 2018, https://doi.org/10.5281/zenodo.1146014.
If you like GNU Parallel:
- Give a demo at your local user group/team/colleagues
- Post the intro videos on Reddit/Diaspora*/forums/blogs/ Identi.ca/Google+/Twitter/Facebook/Linkedin/mailing lists
- Get the merchandise https://gnuparallel.threadless.com/designs/gnu-parallel
- Request or write a review for your favourite blog or magazine
- Request or build a package for your favourite distribution (if it is not already there)
- Invite me for your next conference
If you use programs that use GNU Parallel for research:
- Please cite GNU Parallel in you publications (use –citation)
If GNU Parallel saves you money:
- (Have your company) donate to FSF https://my.fsf.org/donate/
About GNU SQL
GNU sql aims to give a simple, unified interface for accessing databases through all the different databases’ command line clients. So far the focus has been on giving a common way to specify login information (protocol, username, password, hostname, and port number), size (database and table size), and running queries.
The database is addressed using a DBURL. If commands are left out you will get that database’s interactive shell.
When using GNU SQL for a publication please cite:
O. Tange (2011): GNU SQL – A Command Line Tool for Accessing Different Databases Using DBURLs, ;login: The USENIX Magazine, April 2011:29-32.
About GNU Niceload
GNU niceload slows down a program when the computer load average (or other system activity) is above a certain limit. When the limit is reached the program will be suspended for some time. If the limit is a soft limit the program will be allowed to run for short amounts of time before being suspended again. If the limit is a hard limit the program will only be allowed to run when the system is below the limit.
Microsoft update breaks GRUB on dual-boot systems
MERN Stack Development Course Advance Level Course From FIT Computer Institute In Rawalpindi…
Video by via Dailymotion Source https://futureittechnology.com/mern-stack-web-development-courses-in-rawalpindi-Islamabad.html https://futureittechnology.com/ The MERN stack is a popular web development stack that consists of four main technologies: MongoDB: A NoSQL database that stores data in flexible, JSON-like documents. It allows for easy scalability and flexibility in data management.Express.js: A web application framework for Node.js, it simplifies the development of web…
Kemendag Musnahkan Produk Impor Ilegal Senilai Rp20,23 Miliar
Video by via Dailymotion Source Kementerian Perdagangan (Kemendag) di Kantor Kemendag, Jakarta pada Senin, 19 Agustus 2024, memusnahkan produk impor ilegal dengan total nilai mencapai angka Rp20,23 miliar.******Editor : Ipiek RiyantoBaca berita lainnya melalui apps kami: Play Store : https://play.google.com/store/apps/details?id=com.promedia.titiktemu App Store : https://apps.apple.com/app/titik-temu/id6504741782 Go to Source
Comelec, Miru Systems pa rin ang gagamitin sa midterm elections kahit na may reklamo laban sa…
Video by via Dailymotion Source Nanindigan ang Comelec na Miru Systems pa rin ang gagamitin sa #Eleksyon2025. Sa kabila ito ng reklamo sa Ombudsman laban sa chairman ng komsiyon na may kaugnayan dito. 24 Oras is GMA Network’s flagship newscast, anchored by Mel Tiangco, Vicky Morales and Emil Sumangil. It airs on GMA-7 Mondays to…
Christina Onassis, une tragédie grecque
Video by via Dailymotion Source Christina Onassis, 37 ans, est décédée, seule, d’un œdème pulmonaire aigu dans la nuit du samedi 19 novembre 1988 en Argentine. Elle était la fille d’Aristote Onassis, dit Le Grec, l’un des hommes les plus fortunés au monde. Elle aura été à la tête d’une fortune inouïe impliquant des cargos…
Spring – Blender Open Movie
Video by via Dailymotion Source Produced by Blender Studio. Made in Blender 2.8.Get the production files, assets and exclusive making-of videos by joining Blender Studio at https://studio.blender.org — Spring is the story of a shepherd girl and her dog, who face ancient spirits in order to continue the cycle of life. This poetic and visually…