ruby2.3 (2.3.3-1+deb9u4) stretch-security; urgency=high
authorSalvatore Bonaccorso <carnil@debian.org>
Sun, 28 Oct 2018 20:49:57 +0000 (20:49 +0000)
committerSalvatore Bonaccorso <carnil@debian.org>
Sun, 28 Oct 2018 20:49:57 +0000 (20:49 +0000)
commit387c1fc55ae91ad90739a5c7b4c29f5b3527de62
treef6e84f3fa80f9e46fd9233278bf09add8f264ec0
parent4a43f3bf316265e37a004e4e49743f2d5f79af16
parentb6236ee330a1c2f9e911e543dfcbfaf849e090a2
ruby2.3 (2.3.3-1+deb9u4) stretch-security; urgency=high

  * Non-maintainer upload by the Security Team.
  * OpenSSL::X509::Name equality check does not work correctly
    (CVE-2018-16395)
  * pack.c: avoid returning uninitialized String
  * Tainted flags are not propagated in Array#pack and String#unpack with some
    directives (CVE-2018-16396)

[dgit import unpatched ruby2.3 2.3.3-1+deb9u4]
40 files changed:
debian/README.porting
debian/README.source
debian/TODO
debian/changelog
debian/compat
debian/control
debian/copyright
debian/deleted_on_clean.txt
debian/docs
debian/gbp.conf
debian/libruby.stp
debian/libruby2.3.install
debian/libruby2.3.lintian-overrides
debian/libruby2.3.symbols
debian/manpages/gem2.3.1
debian/manpages/gem2.3.rd
debian/manpages/rdoc2.3.1
debian/manpages/rdoc2.3.rd
debian/manpages/testrb2.3.1
debian/manpages/testrb2.3.rd
debian/missing-sources/jquery.js
debian/newruby
debian/patches/debian-changes
debian/patches/series
debian/quick-build.sh
debian/ruby2.3-dev.install
debian/ruby2.3.install
debian/ruby2.3.lintian-overrides
debian/ruby2.3.manpages
debian/rules
debian/sanity_check
debian/source/format
debian/split-tk-out.rb
debian/tests/bundled-gems
debian/tests/control
debian/tests/known-failures.txt
debian/tests/run-all
debian/upstream-changes
debian/upstream-changes.blacklist
debian/watch