Back to curl PTS page

Accepted curl 7.38.0-4+deb8u4 (source amd64 all) into proposed-updates->stable-new, proposed-updates



-----BEGIN PGP SIGNED MESSAGE-----
Hash: SHA512

Format: 1.8
Date: Mon, 01 Aug 2016 12:19:28 +0100
Source: curl
Binary: curl libcurl3 libcurl3-gnutls libcurl3-nss libcurl4-openssl-dev libcurl4-gnutls-dev libcurl4-nss-dev libcurl3-dbg libcurl4-doc
Architecture: source amd64 all
Version: 7.38.0-4+deb8u4
Distribution: jessie-security
Urgency: high
Maintainer: Alessandro Ghedini <ghedo@debian.org>
Changed-By: Alessandro Ghedini <ghedo@debian.org>
Description:
 curl       - command line tool for transferring data with URL syntax
 libcurl3   - easy-to-use client-side URL transfer library (OpenSSL flavour)
 libcurl3-dbg - debugging symbols for libcurl (OpenSSL, GnuTLS and NSS flavours)
 libcurl3-gnutls - easy-to-use client-side URL transfer library (GnuTLS flavour)
 libcurl3-nss - easy-to-use client-side URL transfer library (NSS flavour)
 libcurl4-doc - documentation for libcurl
 libcurl4-gnutls-dev - development files and documentation for libcurl (GnuTLS flavour)
 libcurl4-nss-dev - development files and documentation for libcurl (NSS flavour)
 libcurl4-openssl-dev - development files and documentation for libcurl (OpenSSL flavour)
Changes:
 curl (7.38.0-4+deb8u4) jessie-security; urgency=high
 .
   * Fix TLS session resumption client cert bypass as per CVE-2016-5419
     https://curl.haxx.se/docs/adv_20160803A.html
   * Fix re-using connection with wrong client cert as per CVE-2016-5420
     https://curl.haxx.se/docs/adv_20160803B.html
   * Fix use of connection struct after free as per CVE-2016-5421
     https://curl.haxx.se/docs/adv_20160803C.html
Checksums-Sha1:
 d40a96e1ae309d44a33556a8b9cdbb04162503c5 2655 curl_7.38.0-4+deb8u4.dsc
 6fc4593985baa2e367b3f9af93609083cc709a8e 34628 curl_7.38.0-4+deb8u4.debian.tar.xz
 e41650f06e77e99489a8bb4dbc4f596f961c3ed2 200294 curl_7.38.0-4+deb8u4_amd64.deb
 e104d0ca47abf896204a88750ec9f47d60a3370e 259336 libcurl3_7.38.0-4+deb8u4_amd64.deb
 76619c868e93bfebb920bca2f6bce46de2f94be0 251336 libcurl3-gnutls_7.38.0-4+deb8u4_amd64.deb
 8cb245f53a4436072718a5d9ee0020ea23b54f96 262828 libcurl3-nss_7.38.0-4+deb8u4_amd64.deb
 a5c2d748d984657820fafa79848c05930904c2b7 336408 libcurl4-openssl-dev_7.38.0-4+deb8u4_amd64.deb
 c10813a0c1b75e3171ea15de4a17babc3a87fc14 327928 libcurl4-gnutls-dev_7.38.0-4+deb8u4_amd64.deb
 5c207c4003859a0947750418831fef1af864aa77 340560 libcurl4-nss-dev_7.38.0-4+deb8u4_amd64.deb
 ff67a418c80ac2a125b13d7f5a2b7bdd8f42fc28 3365202 libcurl3-dbg_7.38.0-4+deb8u4_amd64.deb
 b0fd2f2c2e6050aab2ac532b03e17e6aac9f60e5 1066124 libcurl4-doc_7.38.0-4+deb8u4_all.deb
Checksums-Sha256:
 0b99d6f0ee0b92cc34b924252a99ca5bc0d9cf18b3243acf3f2cd4c1391b73e3 2655 curl_7.38.0-4+deb8u4.dsc
 4cd6d52ce3208ce02cba6adae87cbae0c799f55b1eb6812a6f22c5be1fdd52cf 34628 curl_7.38.0-4+deb8u4.debian.tar.xz
 0e080ef30271fe4b305eee9bcbe97e824b12f301e19cab25f42d2a357d12aa0c 200294 curl_7.38.0-4+deb8u4_amd64.deb
 d0060a45e8896a3d4fde73408c807c6af7df867350f8963d15e3685a8d54f1c3 259336 libcurl3_7.38.0-4+deb8u4_amd64.deb
 987d566aa6cb82bdf8d559611a8a51387223e74284f1c28d9e1c07a4ee6e2843 251336 libcurl3-gnutls_7.38.0-4+deb8u4_amd64.deb
 9378a4bc0aee47ec15c96f985a3bfee2d9199cb7b22fcf743e6649c862516a7b 262828 libcurl3-nss_7.38.0-4+deb8u4_amd64.deb
 23e81942e1b5ea6258b80439ec9203436e5addde03a727ea8c9843fdb885e8f2 336408 libcurl4-openssl-dev_7.38.0-4+deb8u4_amd64.deb
 5b5d5b3e8740f5640b38cdda0525f076bb90ae4dfe9f16aee06b809018e60d09 327928 libcurl4-gnutls-dev_7.38.0-4+deb8u4_amd64.deb
 388837ac98ea3b48d92a9636814c5bd30cc6bb8680fb3bf542cb3f5dffd628d5 340560 libcurl4-nss-dev_7.38.0-4+deb8u4_amd64.deb
 f31a847aacaa9ab7c8a1ead1e845e9cd0b3f0d8dbd9601f84e0c46cb073419a2 3365202 libcurl3-dbg_7.38.0-4+deb8u4_amd64.deb
 e2be5703be8fdeab5d0a1ca949faba7e6edf0c38afb4aa4798e049df600cb28a 1066124 libcurl4-doc_7.38.0-4+deb8u4_all.deb
Files:
 2e6d0426370786a72b6f9f5780b52092 2655 web optional curl_7.38.0-4+deb8u4.dsc
 5754b2dce7b7a2a64f5819db79db5231 34628 web optional curl_7.38.0-4+deb8u4.debian.tar.xz
 5dd7dcc987fb82f92be3c7514ac25cb3 200294 web optional curl_7.38.0-4+deb8u4_amd64.deb
 b333b7cfaf3fa3ae85d3b9a50cd3d0a2 259336 libs optional libcurl3_7.38.0-4+deb8u4_amd64.deb
 f26cfca117d2254cead97e0f2c126142 251336 libs optional libcurl3-gnutls_7.38.0-4+deb8u4_amd64.deb
 d02a2f665bbc3c8db78955076b5c07ac 262828 libs optional libcurl3-nss_7.38.0-4+deb8u4_amd64.deb
 c40c69a20f48815388b5666cebfb9ae3 336408 libdevel optional libcurl4-openssl-dev_7.38.0-4+deb8u4_amd64.deb
 2c0f7b13a61c2bac98a15578caa0a188 327928 libdevel optional libcurl4-gnutls-dev_7.38.0-4+deb8u4_amd64.deb
 8776e14d45c6ea6cd2538f6bc162cbb7 340560 libdevel optional libcurl4-nss-dev_7.38.0-4+deb8u4_amd64.deb
 7f013690ab8d9e7db92dac4f4edf27ad 3365202 debug extra libcurl3-dbg_7.38.0-4+deb8u4_amd64.deb
 f5ed09a966ab424b712d8b260c97fa31 1066124 doc optional libcurl4-doc_7.38.0-4+deb8u4_all.deb

-----BEGIN PGP SIGNATURE-----
Version: GnuPG v2

iQIcBAEBCgAGBQJXoMInAAoJEG8My+AhYkcoX/oP/0F/RQ0jEssSR8lNgMAVqj45
6XaJYa19PyyqgzaA3Ni2JN1mk1RzQuY0rn2ROt6kPdyaG1bWbGxVZL4eT/3mIoSR
zBNsUK7+tnAFNZl+157/FKlsIkommiMy7JiCwdvhQpD1RM4kkrrsw44awRCxb277
lRICqEOTMZqn9x5d8h9K7ihwh88LZHelBpHzJrQc88zXzPASxDpMjcfdmZjtBFhu
SkBkOu4k/mCusS5y9pxg15Z1iVLBYCcXk6LvQq+Vo4R4FpecykySm+5EAdINVehy
9ZjaP0W4G0TjQmLi0L/Fjzc6O8kPp7EbDShDA/PNy8PlUG2d6p7IB5XWj8ZjjCTP
w+axOBECx+698LasqkvAQSE4brDamyyTJXB9r4VQxtgYA23C/AhrjGK0LMDleRBL
PNug+evqO+aRPPr4vdcsdV/Oabod8di/NqwByEi9ALl0GztCcm5EA3HRclyJ7wYD
BQtlfF6qi3zPhLEikJ9uvxPneUz4CD5zAnX5T82uXQewD6uD0qRBoX5nb+3dIT7d
q4PMnnrB77OYSJCNNl9fAOxMWYnD3s8Lx99OgxwCBgkOtm5Ag1+lUml8E9W9/cFY
NmwbYOgSQH2uO2SZySMDZJS5CYiywEEduhJIJiApmDA2uWyBtnjCo9kUSxZD+1vA
ssxO/TCJD1XNtbxargKC
=Cbfr
-----END PGP SIGNATURE-----