-----BEGIN PGP SIGNED MESSAGE----- Hash: SHA512 Format: 1.8 Date: Sun, 20 Sep 2020 18:03:02 +0200 Source: curl Binary: curl libcurl3 libcurl3-gnutls libcurl3-nss libcurl4-openssl-dev libcurl4-gnutls-dev libcurl4-nss-dev libcurl3-dbg libcurl4-doc Architecture: source amd64 all Version: 7.52.1-5+deb9u12 Distribution: stretch-security Urgency: high Maintainer: Alessandro Ghedini <ghedo@debian.org> Changed-By: Thorsten Alteholz <debian@alteholz.de> Description: curl - command line tool for transferring data with URL syntax libcurl3 - easy-to-use client-side URL transfer library (OpenSSL flavour) libcurl3-dbg - debugging symbols for libcurl (OpenSSL, GnuTLS and NSS flavours) libcurl3-gnutls - easy-to-use client-side URL transfer library (GnuTLS flavour) libcurl3-nss - easy-to-use client-side URL transfer library (NSS flavour) libcurl4-doc - documentation for libcurl libcurl4-gnutls-dev - development files and documentation for libcurl (GnuTLS flavour) libcurl4-nss-dev - development files and documentation for libcurl (NSS flavour) libcurl4-openssl-dev - development files and documentation for libcurl (OpenSSL flavour) Changes: curl (7.52.1-5+deb9u12) stretch-security; urgency=high . * Non-maintainer upload by the LTS Team. * CVE-2020-8231 in rare circumstances, when using the multi API of curl in combination with CURLOPT_CONNECT_ONLY, the wrong connection might be used when transfering data later Checksums-Sha1: 18d6a47d4b73afca63382ca96e8c4dc3b2832ead 2956 curl_7.52.1-5+deb9u12.dsc 73097952ada80fbaff924c706ba57d1f77c38d00 3504621 curl_7.52.1.orig.tar.gz 4bc9b4a2c6c5db00e00a219d3e0b2a926e5672a1 45088 curl_7.52.1-5+deb9u12.debian.tar.xz 41f3d132af87161c13fcbdb0c7e54cda982e6e63 132024 curl-dbgsym_7.52.1-5+deb9u12_amd64.deb 821fc5c1e8f09f56ca340120a14384fd8c4de79d 11425 curl_7.52.1-5+deb9u12_amd64.buildinfo 33460581370717c7c0118669037f6f4c4991d0b4 227092 curl_7.52.1-5+deb9u12_amd64.deb 63f814766f76170c7626db656bc0863c440c0f1b 4997538 libcurl3-dbg_7.52.1-5+deb9u12_amd64.deb 1f0eb52fd1b340ae80477690b039c28cd815ef8f 290198 libcurl3-gnutls_7.52.1-5+deb9u12_amd64.deb a868375198dd9024f0fede1a8e8129b48a511ff2 295532 libcurl3-nss_7.52.1-5+deb9u12_amd64.deb 9f7844f22552314dc38abca513da227ecd41fd9f 292086 libcurl3_7.52.1-5+deb9u12_amd64.deb 467c94baf14942f6b37db258a24ee6b37a2b592c 828340 libcurl4-doc_7.52.1-5+deb9u12_all.deb c18c67bc8ac47af83a24ba952ebd99c801856ce3 372986 libcurl4-gnutls-dev_7.52.1-5+deb9u12_amd64.deb a0e0d55a2121e7c8fc194235571c8a9fd666dc2c 378444 libcurl4-nss-dev_7.52.1-5+deb9u12_amd64.deb 892d70e62a7d750779714a10be7bedf279bb97ef 374696 libcurl4-openssl-dev_7.52.1-5+deb9u12_amd64.deb Checksums-Sha256: 8eb3a46742209ecc0933b23fd96634a29e95a889cffa3b6eb944350d282cb20a 2956 curl_7.52.1-5+deb9u12.dsc a8984e8b20880b621f61a62d95ff3c0763a3152093a9f9ce4287cfd614add6ae 3504621 curl_7.52.1.orig.tar.gz 048b49e321889c9eb96c68ee58075a872486a98245c59253718c0a8b5a8f1b34 45088 curl_7.52.1-5+deb9u12.debian.tar.xz 34d5c70cb0815309b8ff33f4e5910cee7d3cd27fa2772f499bd0e838ab635e7e 132024 curl-dbgsym_7.52.1-5+deb9u12_amd64.deb b8e4f97a356a848b94de97b3061c5046adc4e0f906ba83fb13d06bf84d077ecb 11425 curl_7.52.1-5+deb9u12_amd64.buildinfo 0c3dcbeeed37274edb8ace1a6d473c292b2cde3015aa8bfe415f3c43f20e8a7c 227092 curl_7.52.1-5+deb9u12_amd64.deb 358286a464ac17272b04198e0b18a7da429f37a553dcf126f283919cc6b7f953 4997538 libcurl3-dbg_7.52.1-5+deb9u12_amd64.deb e1b93bd8845f667cc90431261f4c0aff1e057e6fcf08233cfad2d7ed3f367f6c 290198 libcurl3-gnutls_7.52.1-5+deb9u12_amd64.deb 2cb12411a5f6a0e8b8a3c5130b5045bba131831a5c36511975b2c61c6ef79964 295532 libcurl3-nss_7.52.1-5+deb9u12_amd64.deb 21266d358eb28896a4bc4f21672b65ae21dd6146d03021ca199e91b7de28333d 292086 libcurl3_7.52.1-5+deb9u12_amd64.deb 9952aed908613a552ff02497f72710a876401eb529ef1d21beaf42e2d472a8ef 828340 libcurl4-doc_7.52.1-5+deb9u12_all.deb 21c1c70e8b5ba6ce8b55088cf54e06931590fa0eda7c8703f161dfc549296d72 372986 libcurl4-gnutls-dev_7.52.1-5+deb9u12_amd64.deb 19d0dd76dfe844eb36254cd635b17b9c9759d2e7ad65be2a6557c514ec766fd6 378444 libcurl4-nss-dev_7.52.1-5+deb9u12_amd64.deb dd061fa9b4a8010f619edcad3ac654abfce357a3959ea424196599893c0ba109 374696 libcurl4-openssl-dev_7.52.1-5+deb9u12_amd64.deb Files: 6e58aba5a7de929664b0c333587e0935 2956 web optional curl_7.52.1-5+deb9u12.dsc 4e1ef056e117b4d25f4ec42ac609c0d4 3504621 web optional curl_7.52.1.orig.tar.gz 5462aba818e9a0051ce3503feb3a88c8 45088 web optional curl_7.52.1-5+deb9u12.debian.tar.xz 453c924311ba2cb42f218e909fdd051c 132024 debug extra curl-dbgsym_7.52.1-5+deb9u12_amd64.deb 118098b6c15974ee22a129d56fb20dee 11425 web optional curl_7.52.1-5+deb9u12_amd64.buildinfo f66cbcbd4d82c1e268009cb73e7aa585 227092 web optional curl_7.52.1-5+deb9u12_amd64.deb 61afaafa034cbc5a9616dd72715eb04a 4997538 debug extra libcurl3-dbg_7.52.1-5+deb9u12_amd64.deb d1826e8428a168973b5a26b639121ac6 290198 libs optional libcurl3-gnutls_7.52.1-5+deb9u12_amd64.deb dc1561416985663a48cb5a3836bdc632 295532 libs optional libcurl3-nss_7.52.1-5+deb9u12_amd64.deb ba94a635ff7618d53e0b39b6c2e66766 292086 libs optional libcurl3_7.52.1-5+deb9u12_amd64.deb a5f4ec3499c9a2058690701a735e701a 828340 doc optional libcurl4-doc_7.52.1-5+deb9u12_all.deb 9f051f5ee6995f85d6c9b87751d5940c 372986 libdevel optional libcurl4-gnutls-dev_7.52.1-5+deb9u12_amd64.deb 7ce5076a4b03aacd490776e37100c5e3 378444 libdevel optional libcurl4-nss-dev_7.52.1-5+deb9u12_amd64.deb daa1af8bb798099378b4d932e4f0f773 374696 libdevel optional libcurl4-openssl-dev_7.52.1-5+deb9u12_amd64.deb -----BEGIN PGP SIGNATURE----- iQKnBAEBCgCRFiEEYgH7/9u94Hgi6ruWlvysDTh7WEcFAl9vM1FfFIAAAAAALgAo aXNzdWVyLWZwckBub3RhdGlvbnMub3BlbnBncC5maWZ0aGhvcnNlbWFuLm5ldDYy MDFGQkZGREJCREUwNzgyMkVBQkI5Njk2RkNBQzBEMzg3QjU4NDcTHGRlYmlhbkBh bHRlaG9sei5kZQAKCRCW/KwNOHtYR+e0D/0QPRg1DGWqHKbdbebt9d90vkUsohfy Gjv6iUQFwrjCql0rwxhcbP6aLjY3II5DcRBCnac1E1A6YedyjgzfYCFq9zjZ+oOt +PinlgljBb7ZGdklJav5UNXUBRTivUdS0GbPlzhpo/HtZQvc02zumiAGY2zrmPaR ccqcBiKzzMKdNBXd03AjXG8ogemWY4WQ3PbmntByW3GwBSIlle0rhcCYDuAGPQBu bwo1lKGUsHHHi5mHoWs5Glhn8YPxcd3ztiSxm3D/fjp5sFlgY2+zmjv+aUF8udYJ wy1XNRUuU8PHIA9ycUE1xvJLKaK2EaFYmGTVXif0R+Fk50z6qGLZvgpSBPFHjOoI GHjZNo59KK2KUQnD7HbZU1So8e1sUVzm3sFaXcBnZoYql4ytSExsMuhsBwoSMrKm ZOP14ZzY7QxUsHAWRJrf1Jxp2Cmtdu3upJCYSvDKrdOpit/Y2NHCe/kCnZErviuq iC6UrKOcFghzvuNH5ym0CyofDJWmEeN0IrmYE4xri9FufA78CC0dADj9CQwclhEK NekrPxBomuYkE/dL5TbJSZZYsP3k+NmSGnTvq3Re9L2O4/ZqOCM/0POm/OiNxwtW XLRclk1an6r8DhG/l6fQJ0fA5/YiptSdBbkrR20T+5soenJL8CUGCGbe+XgsC3cL IVpEZu2EFNStvA== =b3Kp -----END PGP SIGNATURE-----