Merge version 2.3.3-1+deb9u6+rpi1 and 2.3.3-1+deb9u7 to produce 2.3.3-1+deb9u7+rpi1 archive/raspbian/2.3.3-1+deb9u7+rpi1 raspbian/2.3.3-1+deb9u7+rpi1
authorRaspbian automatic forward porter <root@raspbian.org>
Tue, 17 Dec 2019 16:14:47 +0000 (16:14 +0000)
committerRaspbian automatic forward porter <root@raspbian.org>
Tue, 17 Dec 2019 16:14:47 +0000 (16:14 +0000)
1  2 
debian/changelog

index df336484647984abe3d40f46764836118b43d474,4e068260dd55b42988314d7478da25836fbaedf3..c703d422c99b5366336519e50fb58a540d70755d
@@@ -1,9 -1,13 +1,20 @@@
- ruby2.3 (2.3.3-1+deb9u6+rpi1) stretch-staging; urgency=medium
++ruby2.3 (2.3.3-1+deb9u7+rpi1) stretch-staging; urgency=medium
 +
 +  [changes brought forward from 2.3.3-1+deb9u1+rpi1 by Peter Michael Green <plugwash@raspbian.org> at Sat, 21 Oct 2017 22:40:37 +0000]
 +  * Disable testsuite.
 +
-  -- Raspbian forward porter <root@raspbian.org>  Thu, 18 Apr 2019 11:04:43 +0000
++ -- Raspbian forward porter <root@raspbian.org>  Tue, 17 Dec 2019 16:14:46 +0000
++
+ ruby2.3 (2.3.3-1+deb9u7) stretch-security; urgency=high
+   * Non-maintainer upload by the Security Team.
+   * Fix for wrong fnmatch patttern (CVE-2019-15845)
+   * Loop with String#scan without creating substring (CVE-2019-16201)
+   * WEBrick: prevent response splitting and header injection (CVE-2019-16254)
+   * lib/shell/command-processor.rb (Shell#[]): prevent unknown command
+     (CVE-2019-16255)
+  -- Salvatore Bonaccorso <carnil@debian.org>  Sun, 15 Dec 2019 17:28:25 +0100
  
  ruby2.3 (2.3.3-1+deb9u6) stretch-security; urgency=medium