Drops (upstream now): 
- Rename "Apply Ruby upstream patch" to fit in between more openssl fixes
- d/p/CVE-2018-16395.patch: CVE-2018-16395                          
- d/p/CVE-2018-16396.patch: CVE-2018-16396
Drops (in Debian now):
- d/p/0012-test-time-tzdata-2018f.patch: Adjust tz tests for new tzdata.


Not in code:
 0001-openssl-buffering.rb-no-RS-when-output.patch |   42 +

Of the formerly undocumented changes of last merge a few were in the
version we now merge, but others are not:

upstream:
 0002-no-ID-cache-in-Init-functions.patch          |  131 ++++
 0003-search-winsock-libraries-explicitly.patch    |   25 
 0004-openssl-search-winsock.patch                 |   39 +
 0007-openssl_missing.h-constified.patch           |   38 +
 0008-reduce-LibreSSL-warnings.patch               |   33 +

not seen
 0006-Workaround-for-old-LibreSSL.patch            |   27 
 0009-openssl-sync-with-upstream-repository.patch  |  643 ++++++++++++++++++++++
 1dfc377ae3b174b043d3f0ed36de57b0296b34d0.patch    |  157 +++++
 rubygems-2388.patch                               |   15 

** CVE added: https://cve.mitre.org/cgi-bin/cvename.cgi?name=2018-16395

** CVE added: https://cve.mitre.org/cgi-bin/cvename.cgi?name=2018-16396

-- 
You received this bug notification because you are a member of Ubuntu
Bugs, which is subscribed to Ubuntu.
https://bugs.launchpad.net/bugs/1806694

Title:
  please merge 2.5.3-3 from debian

To manage notifications about this bug go to:
https://bugs.launchpad.net/ubuntu/+source/ruby2.5/+bug/1806694/+subscriptions

-- 
ubuntu-bugs mailing list
[email protected]
https://lists.ubuntu.com/mailman/listinfo/ubuntu-bugs

Reply via email to