ruby2.3.git
5 years agoFix for wrong fnmatch patttern
Nobuyoshi Nakada [Wed, 12 Dec 2018 05:38:09 +0000 (14:38 +0900)]
Fix for wrong fnmatch patttern

Origin: https://github.com/ruby/ruby/commit/a0a2640b398cffd351f87d3f6243103add66575b
Bug-Debian-Security: https://security-tracker.debian.org/tracker/CVE-2019-15845

* dir.c (file_s_fnmatch): ensure that pattern does not contain a
  NUL character.  https://hackerone.com/reports/449617

Gbp-Pq: Name Fix-for-wrong-fnmatch-patttern.patch

5 years agoCVE-2019-8320-25
Antonio Terceiro [Thu, 1 Oct 2020 13:24:55 +0000 (14:24 +0100)]
CVE-2019-8320-25

Backport of https://github.com/rubygems/rubygems/commit/56c0bbb69e4506bda7ef7f447dfec5db820df20b

Backport of https://github.com/rubygems/rubygems/commit/56c0bbb69e4506bda7ef7f447dfec5db820df20b
addressing, thanks to Leonidas S. Barbosa

CVE-2019-8320
CVE-2019-8321
CVE-2019-8322
CVE-2019-8323
CVE-2019-8324
CVE-2019-8325

Gbp-Pq: Name CVE-2019-8320-25.patch

5 years agodebian-changes
Antonio Terceiro [Thu, 1 Oct 2020 13:24:55 +0000 (14:24 +0100)]
debian-changes

This patch file represents the entire difference between the package as shipped
by Debian and the official upstream sources. The goal is to maintain this file
as small as possible, avoiding non-upstreamed patches at all costs.

The Debian packaging is maintained in the following Git repository:

  http://anonscm.debian.org/gitweb/?p=collab-maint/ruby.git

To obtain a view of the individual commits that affect non-Debian-specific
files, you can clone that repository, and from the master branch, run:

  $ ./debian/upstream-changes

Gbp-Pq: Name debian-changes

5 years agoruby2.3 (2.3.3-1+deb9u9) stretch-security; urgency=high
Utkarsh Gupta [Thu, 1 Oct 2020 13:24:55 +0000 (14:24 +0100)]
ruby2.3 (2.3.3-1+deb9u9) stretch-security; urgency=high

  * Non-maintainer upload by the LTS team.
  * Add patch to fix a potential HTTP request smuggling
    vulnerability in WEBrick. (Fixes: CVE-2020-25613)

[dgit import unpatched ruby2.3 2.3.3-1+deb9u9]

5 years agoImport ruby2.3_2.3.3-1+deb9u9.debian.tar.xz
Utkarsh Gupta [Thu, 1 Oct 2020 13:24:55 +0000 (14:24 +0100)]
Import ruby2.3_2.3.3-1+deb9u9.debian.tar.xz

[dgit import tarball ruby2.3 2.3.3-1+deb9u9 ruby2.3_2.3.3-1+deb9u9.debian.tar.xz]

9 years agoImport ruby2.3_2.3.3.orig.tar.xz
Christian Hofstaedtler [Tue, 22 Nov 2016 12:32:41 +0000 (12:32 +0000)]
Import ruby2.3_2.3.3.orig.tar.xz

[dgit import orig ruby2.3_2.3.3.orig.tar.xz]