summary |
shortlog | log |
commit |
commitdiff |
tree
first ⋅ prev ⋅ next
Utkarsh Gupta [Sun, 19 Sep 2021 03:40:46 +0000 (04:40 +0100)]
ruby2.3 (2.3.3-1+deb9u10) stretch-security; urgency=high
* Add patch to use File.open to fix the OS Command
Injection vulnerability. (Fixes: CVE-2021-31799)
* Add patch to fix StartTLS stripping vulnerability.
(Fixes: CVE-2021-32066)
* Add patch to ignore IP addresses in PASV responses
by default. (Fixes: CVE-2021-31810)
[dgit import unpatched ruby2.3 2.3.3-1+deb9u10]
Utkarsh Gupta [Sun, 19 Sep 2021 03:40:46 +0000 (04:40 +0100)]
Import ruby2.3_2.3.3-1+deb9u10.debian.tar.xz
[dgit import tarball ruby2.3 2.3.3-1+deb9u10 ruby2.3_2.3.3-1+deb9u10.debian.tar.xz]
Christian Hofstaedtler [Tue, 22 Nov 2016 12:32:41 +0000 (12:32 +0000)]
Import ruby2.3_2.3.3.orig.tar.xz
[dgit import orig ruby2.3_2.3.3.orig.tar.xz]