New binary ruby-1.8.5-20061102 is available. (You can get it from "Stable versions snapshots".)
CGI library of ruby 1.8.5 (or earlier) allows remote attackers to cause a denial of service. (See CVE-2006-5467.)
You should update your ruby by this snapshot.