-----BEGIN PGP SIGNED MESSAGE----- Hash: SHA1 Format: 1.8 Date: Sat, 16 Nov 2013 13:04:23 +0100 Source: curl Binary: curl libcurl3 libcurl3-gnutls libcurl3-nss libcurl4-openssl-dev libcurl4-gnutls-dev libcurl4-nss-dev libcurl3-dbg Architecture: source amd64 Version: 7.26.0-1+wheezy5 Distribution: stable-security Urgency: high Maintainer: Alessandro Ghedini <ghedo@debian.org> Changed-By: Alessandro Ghedini <ghedo@debian.org> Description: curl - command line tool for transferring data with URL syntax libcurl3 - easy-to-use client-side URL transfer library (OpenSSL flavour) libcurl3-dbg - debugging symbols for libcurl (OpenSSL, GnuTLS and NSS flavours) libcurl3-gnutls - easy-to-use client-side URL transfer library (GnuTLS flavour) libcurl3-nss - easy-to-use client-side URL transfer library (NSS flavour) libcurl4-gnutls-dev - development files and documentation for libcurl (GnuTLS flavour) libcurl4-nss-dev - development files and documentation for libcurl (NSS flavour) libcurl4-openssl-dev - development files and documentation for libcurl (OpenSSL flavour) Changes: curl (7.26.0-1+wheezy5) stable-security; urgency=high . * Fix OpenSSL checking of a certificate CN or SAN name field when the digital signature verification is turned off as per CVE-2013-4545 http://curl.haxx.se/docs/adv_20131115.html * Set urgency=high accordingly Checksums-Sha1: ff15ce577835a8df889f100d0fda22866b4bbead 2531 curl_7.26.0-1+wheezy5.dsc bf9476a35547febc59548dce94087b96225c086a 34136 curl_7.26.0-1+wheezy5.debian.tar.gz 4ff66085a6369bfa8666a408836452f0ecb622b4 270182 curl_7.26.0-1+wheezy5_amd64.deb 48042bbbb351c723ba7b9e5af461882de5c32d9c 331108 libcurl3_7.26.0-1+wheezy5_amd64.deb ad6b3fa1a118859e342c196f552b216c5777a54b 321886 libcurl3-gnutls_7.26.0-1+wheezy5_amd64.deb 94dcadff84a21665db6a1136e6ba9a492d501c1f 328580 libcurl3-nss_7.26.0-1+wheezy5_amd64.deb 25a0f475bc11c7053e1e1b88d16d6d78ceca0cfd 1270968 libcurl4-openssl-dev_7.26.0-1+wheezy5_amd64.deb f6ff23adb8128fa44a52ca45c9e3604035b4e1e9 1259094 libcurl4-gnutls-dev_7.26.0-1+wheezy5_amd64.deb 0709bd1022f07b915e4a649acfd80e3e4e7b295f 1266690 libcurl4-nss-dev_7.26.0-1+wheezy5_amd64.deb 4afebf12c559b1c34c24cc6a72f44fd14172b022 3296078 libcurl3-dbg_7.26.0-1+wheezy5_amd64.deb Checksums-Sha256: 8b1ecf82f353c66c2baa85aa956b6dc33ba0115a50f7ed78b463360c2b350e86 2531 curl_7.26.0-1+wheezy5.dsc 16dd5bc107781b2dfa1d642dddffcfcc0bccd580a36da169d38869bb238d1e52 34136 curl_7.26.0-1+wheezy5.debian.tar.gz 839c7b53ac675e0dfcfc9e85c447ca49f207b7141b8e3c795d4222487df35f9c 270182 curl_7.26.0-1+wheezy5_amd64.deb 5ab41693f3f2852919cdb26976cd0e93880a3fe0519a0bbf7dc0e479026cd465 331108 libcurl3_7.26.0-1+wheezy5_amd64.deb 026ae6c7562b8cd415fce270b0090513aa5f485a1672d206d6ee507957886dba 321886 libcurl3-gnutls_7.26.0-1+wheezy5_amd64.deb 99e09ef3a687a94385b64d98a4ad3b435cf347b7d92cf6fc302ba101dce9c29c 328580 libcurl3-nss_7.26.0-1+wheezy5_amd64.deb a7c9b1f3d18a36467e63507a9305d5dcaa17e3a69514d76e928d6b7d7a1c171c 1270968 libcurl4-openssl-dev_7.26.0-1+wheezy5_amd64.deb 3575c0b244a5712cb7b00b7ae08ba42cab8b89882b770604473ae1ecbb10d843 1259094 libcurl4-gnutls-dev_7.26.0-1+wheezy5_amd64.deb fae7cb0b937e806f715ded06301cd2b4819c9bf3b713a891814fafd6813d6301 1266690 libcurl4-nss-dev_7.26.0-1+wheezy5_amd64.deb 107cae14ece3e4e7ea931708c00a3749d4efd1b6d1b2ba0c2a50e3ecdf6c0d2c 3296078 libcurl3-dbg_7.26.0-1+wheezy5_amd64.deb Files: f6e073bf4b029ccecc257435cbface54 2531 web optional curl_7.26.0-1+wheezy5.dsc 0977f119dde22fb28b22a6a48b4e02a6 34136 web optional curl_7.26.0-1+wheezy5.debian.tar.gz d2e8f88011d3490c1b2957bb97c654b8 270182 web optional curl_7.26.0-1+wheezy5_amd64.deb 324cca5c52e7f580eb6d5146c24e7439 331108 libs optional libcurl3_7.26.0-1+wheezy5_amd64.deb 85c3f3571eaa3ab2107f85276e80c7ff 321886 libs optional libcurl3-gnutls_7.26.0-1+wheezy5_amd64.deb e0bbea0922a939097874078a46a49edb 328580 libs optional libcurl3-nss_7.26.0-1+wheezy5_amd64.deb 003752e28a0c0211ab108447360fdbdb 1270968 libdevel optional libcurl4-openssl-dev_7.26.0-1+wheezy5_amd64.deb d6df1bc8ec00c707e9db524252520249 1259094 libdevel optional libcurl4-gnutls-dev_7.26.0-1+wheezy5_amd64.deb f4b666e710bf42f60b7bd1e3c740d000 1266690 libdevel optional libcurl4-nss-dev_7.26.0-1+wheezy5_amd64.deb b256defb6e86320737f75ca078b1bd07 3296078 debug extra libcurl3-dbg_7.26.0-1+wheezy5_amd64.deb -----BEGIN PGP SIGNATURE----- Version: GnuPG v1.4.15 (GNU/Linux) iQIcBAEBAgAGBQJSh2VuAAoJEK+lG9bN5XPLMG4P/1cwglmRTnMD4GQeuZ3mqRjs O0AiaEwdEYEpkHbOyf37LD9LJSMdJP9XXKtAYHPOQNtNN68lcioyRJD6vMlmfMV9 eHr4dSF+8A7d/h9irFUQ2RQxlKwZcNbf7ZJaCHDkt0dDUMnFYbYIXkpm5+4CAT0s 24y05lGXIxiJXd5MYiG+OZh6K2piDkUnJlKxaGATOJr/mvvpmLr60j+A0CT762Cc ykiEAKpndajMgpUPZWXnVlJblvwGtHZimHfyb5JMxoUAi1/3mYTjOT8hIyWXwrEK 3Zi++xyXrMLEu5xaUSPdjH8fJCJXUBer4El0cfCLuO+gBssmAIzoSl1cvGv3/Ti4 6tdTwS0zhyNUsDlZ0SGgu5PA7Cb/fe5EYGZ9OnkenABJeb4iNmD+1ePxFHSgpjMI GfXS7ARueHkCehDBGPzBVBJWOQeU3wVLcC+04SJf8aeF2oYLwxM8tT2RtN1n3vgb itWZWQrp8cYZS4Tg4QpNaONjOWVLsV1YlgBOMh/iOPxsNKuQE+Ziw/SIkuZxx/Fl 8jDxi7XBoXedgLcFCDzC4SagO/p5vqJJwaSBAFiMW1m+HLNtHZNR17hGl4TNWY2Z X45r5GGHxvwOBnhGfsqFXOccyUuhATil2q2MwvZqCLQDfUMETP49sj5wKHym54/0 Stbb+B/68je6hFb3UG4y =V4EL -----END PGP SIGNATURE-----