[DRE-commits] [gem2deb] 03/03: 0.5.1 release to unstable

Antonio Terceiro terceiro at moszumanska.debian.org
Thu Nov 21 18:00:02 UTC 2013


This is an automated email from the git hooks/post-receive script.

terceiro pushed a commit to branch master
in repository gem2deb.

commit 25e7449efa21a2b4ff9584c9a82ebf85ba33af8d
Author: Antonio Terceiro <terceiro at debian.org>
Date:   Wed Nov 20 16:19:56 2013 -0300

    0.5.1 release to unstable
---
 debian/changelog |   11 +++++++++++
 1 file changed, 11 insertions(+)

diff --git a/debian/changelog b/debian/changelog
index 1c67b40..bf5b10b 100644
--- a/debian/changelog
+++ b/debian/changelog
@@ -1,3 +1,14 @@
+gem2deb (0.5.1) unstable; urgency=low
+
+  * Don't interpolate arguments for shell commands.
+    This fixes handling of files with weird characters in their names such
+    as ")" and whitespace in general, and improves security against
+    maliciously-crafted filenames which could inject unwanted shell
+    commands in the system that is building a package with gem2deb.
+    (Closes: #729981)
+
+ -- Antonio Terceiro <terceiro at debian.org>  Wed, 20 Nov 2013 16:19:46 -0300
+
 gem2deb (0.5.0) unstable; urgency=low
 
   * Drop Ruby 1.8 support

-- 
Alioth's /usr/local/bin/git-commit-notice on /srv/git.debian.org/git/pkg-ruby-extras/gem2deb.git



More information about the Pkg-ruby-extras-commits mailing list