ruby2.3 (2.3.3-1+deb9u11) stretch-security; urgency=high
authorUtkarsh Gupta <utkarsh@debian.org>
Sun, 5 Dec 2021 23:55:44 +0000 (23:55 +0000)
committerUtkarsh Gupta <utkarsh@debian.org>
Sun, 5 Dec 2021 23:55:44 +0000 (23:55 +0000)
commit521387c2d82fdc8e6079d98236fc4be569fb2aae
tree1c0beb125b953674e4c6c829b2a75105f0618a01
parent4a43f3bf316265e37a004e4e49743f2d5f79af16
parent02a0f5a59e34fc146389852a6688e7e34b0932a5
ruby2.3 (2.3.3-1+deb9u11) stretch-security; urgency=high

  * Add length limit option for methods that parses
    date strings. (Fixes: CVE-2021-41817)
  * When parsing cookies, only decode the values.
    (Fixes: CVE-2021-41819)

[dgit import unpatched ruby2.3 2.3.3-1+deb9u11]
53 files changed:
debian/README.porting
debian/README.source
debian/TODO
debian/changelog
debian/compat
debian/control
debian/copyright
debian/deleted_on_clean.txt
debian/docs
debian/gbp.conf
debian/libruby.stp
debian/libruby2.3.install
debian/libruby2.3.lintian-overrides
debian/libruby2.3.symbols
debian/manpages/gem2.3.1
debian/manpages/gem2.3.rd
debian/manpages/rdoc2.3.1
debian/manpages/rdoc2.3.rd
debian/manpages/testrb2.3.1
debian/manpages/testrb2.3.rd
debian/missing-sources/jquery.js
debian/newruby
debian/patches/CVE-2019-8320-25.patch
debian/patches/CVE-2020-10663.patch
debian/patches/CVE-2020-25613.patch
debian/patches/CVE-2021-31799.patch
debian/patches/CVE-2021-31810.patch
debian/patches/CVE-2021-32066.patch
debian/patches/CVE-2021-41817-followup.patch
debian/patches/CVE-2021-41817.patch
debian/patches/CVE-2021-41819.patch
debian/patches/Fix-for-wrong-fnmatch-patttern.patch
debian/patches/Loop-with-String-scan-without-creating-substrings.patch
debian/patches/WEBrick-prevent-response-splitting-and-header-inject.patch
debian/patches/debian-changes
debian/patches/lib-shell-command-processor.rb-Shell-prevent-unknown.patch
debian/patches/series
debian/quick-build.sh
debian/ruby2.3-dev.install
debian/ruby2.3.install
debian/ruby2.3.lintian-overrides
debian/ruby2.3.manpages
debian/rules
debian/sanity_check
debian/source/format
debian/split-tk-out.rb
debian/tests/bundled-gems
debian/tests/control
debian/tests/known-failures.txt
debian/tests/run-all
debian/upstream-changes
debian/upstream-changes.blacklist
debian/watch