-----BEGIN PGP SIGNED MESSAGE----- Hash: SHA256 Format: 1.8 Date: Sat, 04 Jul 2020 00:07:58 +0530 Source: ruby2.5 Binary: libruby2.5 libruby2.5-dbgsym ruby2.5 ruby2.5-dbgsym ruby2.5-dev ruby2.5-doc Architecture: source amd64 all Version: 2.5.5-3+deb10u2 Distribution: buster-security Urgency: high Maintainer: Debian Ruby Team <pkg-ruby-extras-maintainers@lists.alioth.debian.org> Changed-By: Utkarsh Gupta <utkarsh@debian.org> Description: libruby2.5 - Libraries necessary to run Ruby 2.5 ruby2.5 - Interpreter of object-oriented scripting language Ruby ruby2.5-dev - Header files for compiling extension modules for the Ruby 2.5 ruby2.5-doc - Documentation for Ruby 2.5 Changes: ruby2.5 (2.5.5-3+deb10u2) buster-security; urgency=high . * Non-maintainer upload by the Security Team. * Add patch to fix: - CVE-2020-10663: unsafe object creation vulnerability in JSON. - CVE-2020-10933: do not return uninitialized buffer. Checksums-Sha1: d5bfb99c3604856ff15cbb0523220abced541175 2482 ruby2.5_2.5.5-3+deb10u2.dsc c477ffe8f8ed605036df6c8892bd3c800b8e9722 10208264 ruby2.5_2.5.5.orig.tar.xz f07a4caa00d7604d3e709823e20103c0483524f8 120756 ruby2.5_2.5.5-3+deb10u2.debian.tar.xz 67e241e78b48ad4f75ecd49e5c69efda9d6fa898 6205672 libruby2.5-dbgsym_2.5.5-3+deb10u2_amd64.deb 2586f11b9486e37ed6c53905fbbc6ddbf65ea7b8 3436404 libruby2.5_2.5.5-3+deb10u2_amd64.deb ee850fa933ff40db16098431e30ceec6befe91b1 5176 ruby2.5-dbgsym_2.5.5-3+deb10u2_amd64.deb 521aba886073720095f689fa408be9e7cf0c80fa 415268 ruby2.5-dev_2.5.5-3+deb10u2_amd64.deb 2c135b019765d99e845d73fbf20af34e8990082e 2149312 ruby2.5-doc_2.5.5-3+deb10u2_all.deb d3af2ff716a36f68cde7298aca63d350a5797755 8125 ruby2.5_2.5.5-3+deb10u2_amd64.buildinfo 1a1b6c734e01d779cceb2567b19e0d3775c7829c 400076 ruby2.5_2.5.5-3+deb10u2_amd64.deb Checksums-Sha256: 2d0d5dd37c3c148231ffbb85a2b827775437742894b379ce29ee2d136a819000 2482 ruby2.5_2.5.5-3+deb10u2.dsc a49a222bbeeeb0191ae043a509cd05137869f971a33fef74d3c0aaae95170877 10208264 ruby2.5_2.5.5.orig.tar.xz 6dd2cd4c5c898df8d5b35c759eb100b25f8292a6ac33cedd31f161af48a59ba0 120756 ruby2.5_2.5.5-3+deb10u2.debian.tar.xz 82f09550d7e74c812f2b25d6ec507bf46b41bf6f39dba4d12962fb6da93ce849 6205672 libruby2.5-dbgsym_2.5.5-3+deb10u2_amd64.deb 08a37d8a4d727dc2cf7a4d886d1aba5fe62f1bd8fc38bae76c9118a672e4ee72 3436404 libruby2.5_2.5.5-3+deb10u2_amd64.deb a6df82befbbf5266e9a08407f7c3ae060595052a63f3ce94b95a21c298397ff0 5176 ruby2.5-dbgsym_2.5.5-3+deb10u2_amd64.deb 7ed2b70841084ecba025ff3b4556237aedc266649e505b759e30f1076371ad4d 415268 ruby2.5-dev_2.5.5-3+deb10u2_amd64.deb 04cc4dd0c4dc902ec26a4f6559d37189432cf2dd90c659be15517eeddd2ca7f7 2149312 ruby2.5-doc_2.5.5-3+deb10u2_all.deb 2a3bed855883523572dbabb9813c754133b65df17bc5fb2345de14ee022944c8 8125 ruby2.5_2.5.5-3+deb10u2_amd64.buildinfo 622527ee7d82fcd6b158d63ac92f7543e571f2f1cae7e0b415fb77eac65d749c 400076 ruby2.5_2.5.5-3+deb10u2_amd64.deb Files: a17eb5d27fefb4892e42014f2047020b 2482 ruby optional ruby2.5_2.5.5-3+deb10u2.dsc 9a1922884905ac8be7ddf8de1408472d 10208264 ruby optional ruby2.5_2.5.5.orig.tar.xz 66e487f53ec911423527b5fe3e671af2 120756 ruby optional ruby2.5_2.5.5-3+deb10u2.debian.tar.xz 1539ab7874166bb4d2d7780a7634073a 6205672 debug optional libruby2.5-dbgsym_2.5.5-3+deb10u2_amd64.deb c89e108784879861c720405a3a47941e 3436404 libs optional libruby2.5_2.5.5-3+deb10u2_amd64.deb f0e23525681ef51dddcf2972fb259b8f 5176 debug optional ruby2.5-dbgsym_2.5.5-3+deb10u2_amd64.deb 0fc727ef275993cd7a937da1e62c5bd1 415268 ruby optional ruby2.5-dev_2.5.5-3+deb10u2_amd64.deb 5ed1a1ed96226ccc392d6c2e2323cb14 2149312 doc optional ruby2.5-doc_2.5.5-3+deb10u2_all.deb 9aee78d3aa79e608cca031e9eb5e1aef 8125 ruby optional ruby2.5_2.5.5-3+deb10u2_amd64.buildinfo e45d87068ef8d7fbfbfa279eb51a4277 400076 ruby optional ruby2.5_2.5.5-3+deb10u2_amd64.deb -----BEGIN PGP SIGNATURE----- iQJHBAEBCAAxFiEEbJ0QSEqa5Mw4X3xxgj6WdgbDS5YFAl8AmF4THHV0a2Fyc2hA ZGViaWFuLm9yZwAKCRCCPpZ2BsNLllGUD/0TIWYvBFgP4fFai8tPBSEq0db79u0s IQeH/KZtKq+Tew0hmR4r2vLavhccpGeImFws4saa+1/iriF82Poh95hjZ10qC42N 0+gv/PzyFjquM+12Y40jdiU7ZOs5iqpzBtaK2JFDIuXHuE6UJGsPXJKz5cR2id35 8PV6DLSewxBvcdy0Qc3yB9SV2trnLTw4hYH9kJCVGpXAIeaD8ZY/JMYJeuUs3NzN 59b5d60iWjA3NmbNgMarky9MtM6pZuo+RsA6CXfvMLKca6dpXnnsSdnrmbBUPfAv m/ulcdD08tJ4dMhPO/U3qZ+WTtwRxqhi1CeTJWIj9F8B36KE/zz3xv+1UsxSH7XX kkqFCZuzUfq2mG2LheUOsug98uO9Cr3gOb5uhI/rM36NJR7xfy3rs/wkqE9WDiGk P9OyTlN02zQymWbK+RGXqIHNHFxXtBLexGUoJc/no8SFk6qWfajVcWLM3jBYgABi zV/uz+jqnZNI/vUUS2hU8skyseo3I+bnUGY7srv7a4aUiaz18NLk853k2A7xfQqQ Twgd/yVzEQmc9Tkp7gIGt1cP4frbnShs3URQf0usNIaTjg3ViV5JVVDzXDYWnf/o k1La8HELqQ9blpl8IR1xq29RVDn1UCEtOgh2OFNe4frDXh4jF9SBuKUOzmOQqg3S jaIkGARP8yDJOg== =F7NG -----END PGP SIGNATURE-----