ruby2.3 (2.3.3-1+deb9u7) stretch-security; urgency=high
authorSalvatore Bonaccorso <carnil@debian.org>
Sun, 15 Dec 2019 16:28:25 +0000 (16:28 +0000)
committerSalvatore Bonaccorso <carnil@debian.org>
Sun, 15 Dec 2019 16:28:25 +0000 (16:28 +0000)
commitd263c35f4ea39a81ae9cffb47d34ea981a1657c7
treeda8bb18bc84e800c758ab451c0d072b15433bcf3
parent4a43f3bf316265e37a004e4e49743f2d5f79af16
parent095cd276dc14f27f3e3ce27e5d8ad72f8871d819
ruby2.3 (2.3.3-1+deb9u7) stretch-security; urgency=high

  * Non-maintainer upload by the Security Team.
  * Fix for wrong fnmatch patttern (CVE-2019-15845)
  * Loop with String#scan without creating substring (CVE-2019-16201)
  * WEBrick: prevent response splitting and header injection (CVE-2019-16254)
  * lib/shell/command-processor.rb (Shell#[]): prevent unknown command
    (CVE-2019-16255)

[dgit import unpatched ruby2.3 2.3.3-1+deb9u7]
45 files changed:
debian/README.porting
debian/README.source
debian/TODO
debian/changelog
debian/compat
debian/control
debian/copyright
debian/deleted_on_clean.txt
debian/docs
debian/gbp.conf
debian/libruby.stp
debian/libruby2.3.install
debian/libruby2.3.lintian-overrides
debian/libruby2.3.symbols
debian/manpages/gem2.3.1
debian/manpages/gem2.3.rd
debian/manpages/rdoc2.3.1
debian/manpages/rdoc2.3.rd
debian/manpages/testrb2.3.1
debian/manpages/testrb2.3.rd
debian/missing-sources/jquery.js
debian/newruby
debian/patches/CVE-2019-8320-25.patch
debian/patches/Fix-for-wrong-fnmatch-patttern.patch
debian/patches/Loop-with-String-scan-without-creating-substrings.patch
debian/patches/WEBrick-prevent-response-splitting-and-header-inject.patch
debian/patches/debian-changes
debian/patches/lib-shell-command-processor.rb-Shell-prevent-unknown.patch
debian/patches/series
debian/quick-build.sh
debian/ruby2.3-dev.install
debian/ruby2.3.install
debian/ruby2.3.lintian-overrides
debian/ruby2.3.manpages
debian/rules
debian/sanity_check
debian/source/format
debian/split-tk-out.rb
debian/tests/bundled-gems
debian/tests/control
debian/tests/known-failures.txt
debian/tests/run-all
debian/upstream-changes
debian/upstream-changes.blacklist
debian/watch