-----BEGIN PGP SIGNED MESSAGE----- Hash: SHA256 Format: 1.8 Date: Thu, 12 Jul 2018 10:25:56 +0100 Source: ruby-sprockets Binary: ruby-sprockets Architecture: source all Version: 2.12.3-1+deb8u1 Distribution: jessie-security Urgency: high Maintainer: Debian Ruby Extras Maintainers <pkg-ruby-extras-maintainers@lists.alioth.debian.org> Changed-By: Chris Lamb <lamby@debian.org> Description: ruby-sprockets - Rack-based asset packaging system Closes: 901913 Changes: ruby-sprockets (2.12.3-1+deb8u1) jessie-security; urgency=high . * CVE-2018-3760: Do not respond to http requests asking for a `file://`. (Closes: #901913) Checksums-Sha1: 52ecc4eb8d3c079089fada2e77c560eb8c0e335e 2195 ruby-sprockets_2.12.3-1+deb8u1.dsc e291238605246568efce415e9153f46fccb86bed 39719 ruby-sprockets_2.12.3.orig.tar.gz 3592888cfbb5356492400d8dfd15f103154957d5 5024 ruby-sprockets_2.12.3-1+deb8u1.debian.tar.xz 257157b60190a100d7aeb9293744f5f31bb14a67 40020 ruby-sprockets_2.12.3-1+deb8u1_all.deb Checksums-Sha256: 25cbaa4e909387fc17581732a595185b81f81019dfb19cd997890a0b9710dd69 2195 ruby-sprockets_2.12.3-1+deb8u1.dsc ea645e2bbb04385dc3c19da956d3b6f561494d8d2e90a6f8c66aa7667b5da331 39719 ruby-sprockets_2.12.3.orig.tar.gz 074721c5c9bc7a358d6295ad8d264f2aedcf8a20f107f4b428fcc8afaf811f58 5024 ruby-sprockets_2.12.3-1+deb8u1.debian.tar.xz 78e1bc308e2a19af7b15abae1e41e56c5dfa435b5ce2934ab1ace1cff2cb4734 40020 ruby-sprockets_2.12.3-1+deb8u1_all.deb Files: 662eb11845b06b49be56439f8033a181 2195 ruby optional ruby-sprockets_2.12.3-1+deb8u1.dsc 62cd88f873d0abfe39b822088518fed7 39719 ruby optional ruby-sprockets_2.12.3.orig.tar.gz e45262d7a420b977addefe70ba4e8d31 5024 ruby optional ruby-sprockets_2.12.3-1+deb8u1.debian.tar.xz d7cb30ceac19e8d46c310c48d98632fa 40020 ruby optional ruby-sprockets_2.12.3-1+deb8u1_all.deb -----BEGIN PGP SIGNATURE----- iQIzBAEBCAAdFiEEwv5L0nHBObhsUz5GHpU+J9QxHlgFAltHH4oACgkQHpU+J9Qx HlintBAAvjp7Jfr9AFiRxtNSX4CX+dtnIa/aC1UGskmehLtrsSCAJoSCvBo9LHmR 01kUpRvbPdKVNL2blHZ0C0SD7iHsK5mjf0zfJYUMhpca6yTLAb+0DUMOSEtN+7ZE d69ssL9S9tnDClqh7e8R/rVGFjKQDmT0TjWYcw0lCZ43q8TK2OdWTUJHcHec+OvE WYUtKb90QkE2nLwOM+XLV4mfZd6XmILtdwx0SJv2/33jfFyDv1SJMwC5bJr1iU54 clcIO8Ug053p5trmLVh7Er1V299uUgsbExtq3Us2XSf8TFXQAcr757o6LD61atIh 2u5hsukkQcgDm4plurWkzPyn3m6dyDvV6yH9YKtt1+u8tDbmuIgQuPaYr4U1fll0 abPtSUDzZYD5eWthM1OfpDnZgwuzCOPDWwwR+0vmvnJdqZSpJnfiy5ybXcGhmChO bUJpDg9wH8bpU7BuXDgOmznKKnzG+e10t13frqtlw6QrPi7V/yd93hkRKLTtlCNl aZTEMTPOBncq3XiVQyNmZyG9f4noiKN6f7cdugWqdBL5pwajFS4blkQu75o0Uc9Z GUIlwi95lr2X/8CQ7/2WtoZuuUMCqO2k9stpnZ55lcNzNhLzRhwanhAFpTez7EBC wge4otEaVoWrZ6R4a3FCb3jRJV6ozRilydE/MVNUWKB3avl7m1k= =d8sB -----END PGP SIGNATURE-----