-----BEGIN PGP SIGNED MESSAGE----- Hash: SHA256 Format: 1.8 Date: Tue, 24 Sep 2019 17:22:04 +1000 Source: ruby-nokogiri Binary: ruby-nokogiri Architecture: source amd64 Version: 1.6.3.1+ds-1+deb8u1 Distribution: jessie-security Urgency: medium Maintainer: Debian Ruby Extras Maintainers <pkg-ruby-extras-maintain...@lists.alioth.debian.org> Changed-By: Brian May <b...@debian.org> Description: ruby-nokogiri - HTML, XML, SAX, and Reader parser for Ruby Changes: ruby-nokogiri (1.6.3.1+ds-1+deb8u1) jessie-security; urgency=medium . * Non-maintainer upload by the LTS Team. * Fix CVE-2019-5477: Command injection vulnerability in Nokogiri allows commands to be executed in a subprocess by Ruby's `Kernel.open` method. Checksums-Sha1: ac00f085aba0944d8a8f9494f7407b6f241efce1 2188 ruby-nokogiri_1.6.3.1+ds-1+deb8u1.dsc 5153f692f89d1c2c4e16716633d5371e7b780014 465163 ruby-nokogiri_1.6.3.1+ds.orig.tar.gz b307b413ef6f36a6a24a240e0a80cf07b7d2105f 7048 ruby-nokogiri_1.6.3.1+ds-1+deb8u1.debian.tar.xz 9c415334c42a2fec5577ca468fa6236f31f67bc2 103286 ruby-nokogiri_1.6.3.1+ds-1+deb8u1_amd64.deb Checksums-Sha256: 5c30cbd1bfcd2f7afd015458f1c14f5547db6eaf0981cf37a4d52bb8bc47dda8 2188 ruby-nokogiri_1.6.3.1+ds-1+deb8u1.dsc b0696bfad08cf8ac90d3db33b638ec96219f7d7552ae74cb83e3364944f986e4 465163 ruby-nokogiri_1.6.3.1+ds.orig.tar.gz 0f493427b58c4adab92d0434ea70ff9854fd0ecd20589f8bcc0fc5cd66f79d79 7048 ruby-nokogiri_1.6.3.1+ds-1+deb8u1.debian.tar.xz 23930380666c207d198feba0dbf42ba8b789e2ebe14ade93ac8aa1c589175916 103286 ruby-nokogiri_1.6.3.1+ds-1+deb8u1_amd64.deb Files: 6fe6a3f8bc3b25f26d4fd77dfd0a9648 2188 ruby optional ruby-nokogiri_1.6.3.1+ds-1+deb8u1.dsc 66ddd53b9496a1d56b619eafe390fd6b 465163 ruby optional ruby-nokogiri_1.6.3.1+ds.orig.tar.gz c682690f85d1139711c290708664244a 7048 ruby optional ruby-nokogiri_1.6.3.1+ds-1+deb8u1.debian.tar.xz cddc3139332e71a8837a295318f57205 103286 ruby optional ruby-nokogiri_1.6.3.1+ds-1+deb8u1_amd64.deb
-----BEGIN PGP SIGNATURE----- iQIzBAEBCAAdFiEEKpwfR8DOwu5vyB4TKpJZkldkSvoFAl2MDA4ACgkQKpJZkldk SvqsgxAAk5yYTYklTDTd/Dluy3mKoLxXKceERC564rrDDiTsxVeg+VUFs31sU/e/ k5XwN83XIv5efk+DX3Nk7Ib7QwU71GbXN2CQmmidIpuxA7zIQbU7rShjQmhkclAS gMb3hTFNBOYqT962nnjKvyVQMg3xMeIN5NwwRSgWFl0qkq93wsGV9IOMRA6T6qkV TsQKavZPQ4AUm8VAWrVWQKHXUS1KDJRKlkd9lK+6GMEM6o61gWVCoCh2joiQ3x6J GFg5y9xU04Nbcb7sohT0LaINNqK9hnVnghRfNTDpW3h6cIo/VKNX3Rdk/TLbQP9w oqdNhANMaL2ptYS1mcCVwd0HQnwZwwIVaApcLJbJi5SG7BTqq3aJ6xXKxMwbaEPw 3rnwFk5RFR5kSacPrIY0OW7RBjpz9yfR39Z2mEcB7FgTAL2nM77gHx0u0N5gEf6t scoHKYSU5fu+cXvkoToMANj2W9i2kHuffL7I95ZkkV/YBtwvqljljGhJLRT8Si/y BpE9dJYulxtl0mw+gewNAqHQtL8wqGjbR4wBswWRUuHHxnHwZ0VofiTfWKtXUPan XCFzEYS+NlU9sFA9KT1Ng5BBarKf53iY9Ohd3CRZtdTyRK9FBOpTvSyKEcobKaeN VX9OFHagKyl0RWdgWpUEL25k6knyXo3FawPvql+7QECU2NYBNMI= =E665 -----END PGP SIGNATURE-----