Format: 1.8 Date: Wed, 03 Apr 2019 12:30:36 -0300 Source: ruby2.3 Binary: ruby2.3 libruby2.3 libruby2.3-dbg ruby2.3-dev ruby2.3-doc ruby2.3-tcltk Architecture: armhf Version: 2.3.1-2~16.04.12 Distribution: xenial Urgency: medium Maintainer: Launchpad Build Daemon Changed-By: Leonidas S. Barbosa Description: libruby2.3 - Libraries necessary to run Ruby 2.3 libruby2.3-dbg - Debugging symbols for libruby2.3 ruby2.3 - Interpreter of object-oriented scripting language Ruby ruby2.3-dev - Header files for compiling extension modules for the Ruby 2.3 ruby2.3-doc - Documentation for Ruby 2.3 ruby2.3-tcltk - Ruby/Tk for Ruby 2.3 Changes: ruby2.3 (2.3.1-2~16.04.12) xenial-security; urgency=medium . * SECURITY UPDATE: Delete directory using symlink when decompressing tar, Escape sequence injection vulnerability in gem owner, Escape sequence injection vulnerability in API response handling, Arbitrary code exec, Escape sequence injection vulnerability in errors - debian/patches/CVE-2019-8320-25.patch: fix in lib/rubygems/command_manager.rb, lib/rubygems/commands/owner_command.rb, lib/rubygems/gemcutter_utilities.rb, lib/rubygems/installer.rb, lib/rubygems/package.rb, test/rubygems/test_gem_package.rb, test/rubygems/test_gem_installer.rb, test/rubygems/test_gem_text.rb. - CVE-2019-8320 - CVE-2019-8321 - CVE-2019-8322 - CVE-2019-8323 - CVE-2019-8324 - CVE-2019-8325 * Fixing expired certification that causes tests to fail - debian/patches/fixing_expired_SSL_certificates.patch: fix in test/net/imap/cacert.pen, test/net/imap/server.crt, test/net/imap/server.key. * Added lisbon_tz test to excluded tests - debian/patches/0001-excluding_lisbon_tz_test.patch: test/excludes/TestTimeTZ.rb. * Fixing symlink expanding issue that makes some tests and gems fails - debian/patches/fixing_symlink_expanding_issue.patch: fix in lib/rubygems/package.rb, test/rubygems/test_gem_package.rb. Checksums-Sha1: 02efebda5fd3c25a77be9d5dba866fe6fe5477d3 3045240 libruby2.3-dbg_2.3.1-2~16.04.12_armhf.deb 87378ab513f37930db92ef52697fb48c0ca5708c 954 libruby2.3-dbgsym_2.3.1-2~16.04.12_armhf.ddeb 4e101a612f3669ebfa5047e664c2ffd0b890c79c 2762286 libruby2.3_2.3.1-2~16.04.12_armhf.deb 5bafbd50617daa6333d05007ef458a60a2c5089e 984 ruby2.3-dbgsym_2.3.1-2~16.04.12_armhf.ddeb 525155897d63958987f5191b2d03aeeef9667ea4 978 ruby2.3-dev-dbgsym_2.3.1-2~16.04.12_armhf.ddeb b311566c5cd55b71cf293aa2d945295b7b4f7698 908694 ruby2.3-dev_2.3.1-2~16.04.12_armhf.deb df1b825f6a60f4aff222f083ff71fc3bd8e13e1f 950 ruby2.3-tcltk-dbgsym_2.3.1-2~16.04.12_armhf.ddeb 827189dd755f4d8c8f9ffaf49ad7fd46687e8ce3 270882 ruby2.3-tcltk_2.3.1-2~16.04.12_armhf.deb 65ad5ba363d2e8ce10d14696b613179863fc2c68 40924 ruby2.3_2.3.1-2~16.04.12_armhf.deb Checksums-Sha256: 54e90a9ad513839d44a205a809190cd636283c0feb35078495bd1eeeed78e5c9 3045240 libruby2.3-dbg_2.3.1-2~16.04.12_armhf.deb 5def07fd00caf8824515b6fe6a5b6b42c957a64446455314b29ea388c3baa527 954 libruby2.3-dbgsym_2.3.1-2~16.04.12_armhf.ddeb 5ac8e5dda4c98c39192b7b1425406b8be6dbebd6b929cd7fd66635033086e1c0 2762286 libruby2.3_2.3.1-2~16.04.12_armhf.deb b7bceed16c4c37e8b2aa85b844d1b1b3cdf1ad39f7932d7386ff446f8ca8acf8 984 ruby2.3-dbgsym_2.3.1-2~16.04.12_armhf.ddeb 0ded39195015e95f35365609928aec9995c813fbbe54253fb9f53a933d34dcea 978 ruby2.3-dev-dbgsym_2.3.1-2~16.04.12_armhf.ddeb 9452901dea19c4c58ca689e03591be53ac1ad0fb03cae4a232130f7f06f5cec0 908694 ruby2.3-dev_2.3.1-2~16.04.12_armhf.deb 927e183615f303929f8e4bf384b9c798b6ae9f10a1e2c65e5f7f331abca352bb 950 ruby2.3-tcltk-dbgsym_2.3.1-2~16.04.12_armhf.ddeb ebaf6d0f27effe00bfc9d3fa50337c18617c884db6de0cfcc543c63ef7930c2b 270882 ruby2.3-tcltk_2.3.1-2~16.04.12_armhf.deb f1c4a69650323551ec77cb2ba92ec02abfff7171344e14778a9b11a2607b2874 40924 ruby2.3_2.3.1-2~16.04.12_armhf.deb Files: dda726052fb375eebc041bdd3a74bd1b 3045240 debug optional libruby2.3-dbg_2.3.1-2~16.04.12_armhf.deb 829a87064ccedf9b4e6b00bb92aa7e9a 954 libs extra libruby2.3-dbgsym_2.3.1-2~16.04.12_armhf.ddeb 1f20b845c0363106bc27ca1a513cc88a 2762286 libs optional libruby2.3_2.3.1-2~16.04.12_armhf.deb 401283c55797d07a744a28993e36f5ae 984 ruby extra ruby2.3-dbgsym_2.3.1-2~16.04.12_armhf.ddeb 5d805d73c947e802d337984fd8a08312 978 ruby extra ruby2.3-dev-dbgsym_2.3.1-2~16.04.12_armhf.ddeb a0def07475c683a736c9de0555d799bf 908694 ruby optional ruby2.3-dev_2.3.1-2~16.04.12_armhf.deb f4a8a731b230de486ca93aa0205522f4 950 ruby extra ruby2.3-tcltk-dbgsym_2.3.1-2~16.04.12_armhf.ddeb d04fed927b545c8bb922ca5eaf89873a 270882 ruby optional ruby2.3-tcltk_2.3.1-2~16.04.12_armhf.deb d91d65e35996b60e1be0053d54a3272d 40924 ruby optional ruby2.3_2.3.1-2~16.04.12_armhf.deb