ruby2.3 (2.3.3-1+deb9u10) stretch-security; urgency=high
authorUtkarsh Gupta <utkarsh@debian.org>
Sun, 19 Sep 2021 03:40:46 +0000 (04:40 +0100)
committerUtkarsh Gupta <utkarsh@debian.org>
Sun, 19 Sep 2021 03:40:46 +0000 (04:40 +0100)
commita2c1a329d6bae3426a3df2975a1955b3bc96cbf3
treeb1b1fd9a7d4721ecc1e0f528eaa1e0e08b49c712
parent4a43f3bf316265e37a004e4e49743f2d5f79af16
parent3832638202f0eb45a78ea8d626423ba471c9b039
ruby2.3 (2.3.3-1+deb9u10) stretch-security; urgency=high

  * Add patch to use File.open to fix the OS Command
    Injection vulnerability. (Fixes: CVE-2021-31799)
  * Add patch to fix StartTLS stripping vulnerability.
    (Fixes: CVE-2021-32066)
  * Add patch to ignore IP addresses in PASV responses
    by default. (Fixes: CVE-2021-31810)

[dgit import unpatched ruby2.3 2.3.3-1+deb9u10]
50 files changed:
debian/README.porting
debian/README.source
debian/TODO
debian/changelog
debian/compat
debian/control
debian/copyright
debian/deleted_on_clean.txt
debian/docs
debian/gbp.conf
debian/libruby.stp
debian/libruby2.3.install
debian/libruby2.3.lintian-overrides
debian/libruby2.3.symbols
debian/manpages/gem2.3.1
debian/manpages/gem2.3.rd
debian/manpages/rdoc2.3.1
debian/manpages/rdoc2.3.rd
debian/manpages/testrb2.3.1
debian/manpages/testrb2.3.rd
debian/missing-sources/jquery.js
debian/newruby
debian/patches/CVE-2019-8320-25.patch
debian/patches/CVE-2020-10663.patch
debian/patches/CVE-2020-25613.patch
debian/patches/CVE-2021-31799.patch
debian/patches/CVE-2021-31810.patch
debian/patches/CVE-2021-32066.patch
debian/patches/Fix-for-wrong-fnmatch-patttern.patch
debian/patches/Loop-with-String-scan-without-creating-substrings.patch
debian/patches/WEBrick-prevent-response-splitting-and-header-inject.patch
debian/patches/debian-changes
debian/patches/lib-shell-command-processor.rb-Shell-prevent-unknown.patch
debian/patches/series
debian/quick-build.sh
debian/ruby2.3-dev.install
debian/ruby2.3.install
debian/ruby2.3.lintian-overrides
debian/ruby2.3.manpages
debian/rules
debian/sanity_check
debian/source/format
debian/split-tk-out.rb
debian/tests/bundled-gems
debian/tests/control
debian/tests/known-failures.txt
debian/tests/run-all
debian/upstream-changes
debian/upstream-changes.blacklist
debian/watch