-----BEGIN PGP SIGNED MESSAGE----- Hash: SHA1 Format: 1.8 Date: Sat, 16 Nov 2013 13:15:23 +0100 Source: curl Binary: curl libcurl3 libcurl3-gnutls libcurl4-openssl-dev libcurl4-gnutls-dev libcurl3-dbg Architecture: source amd64 Version: 7.21.0-2.1+squeeze5 Distribution: oldstable-security Urgency: high Maintainer: Ramakrishnan Muthukrishnan <rkrishnan@debian.org> Changed-By: Alessandro Ghedini <ghedo@debian.org> Description: curl - Get a file from an HTTP, HTTPS or FTP server libcurl3 - Multi-protocol file transfer library (OpenSSL) libcurl3-dbg - libcurl compiled with debug symbols libcurl3-gnutls - Multi-protocol file transfer library (GnuTLS) libcurl4-gnutls-dev - Development files and documentation for libcurl (GnuTLS) libcurl4-openssl-dev - Development files and documentation for libcurl (OpenSSL) Changes: curl (7.21.0-2.1+squeeze5) oldstable-security; urgency=high . * Fix OpenSSL checking of a certificate CN or SAN name field when the digital signature verification is turned off as per CVE-2013-4545 http://curl.haxx.se/docs/adv_20131115.html * Set urgency=high accordingly Checksums-Sha1: 1bf89365762375824c1756935854f8ea7fb3208e 2168 curl_7.21.0-2.1+squeeze5.dsc c67eb31ec7be886ad5bfd3174a24eba1e3a2f141 102344 curl_7.21.0-2.1+squeeze5.debian.tar.gz 4cfcc084ca4c5176e3178052b62985e29c7188c2 229292 curl_7.21.0-2.1+squeeze5_amd64.deb 917aaeba57356822663689c52f3cf162c3cfed95 285296 libcurl3_7.21.0-2.1+squeeze5_amd64.deb fa72b9a8e2592f62da560e596ab8e61aa4a81baf 266244 libcurl3-gnutls_7.21.0-2.1+squeeze5_amd64.deb 13aa32992e1f23cc363f6ef71b0ea5d9186efd79 1100160 libcurl4-openssl-dev_7.21.0-2.1+squeeze5_amd64.deb 895252f0b42542e2a19cf57cc965ae8d2904028f 1075850 libcurl4-gnutls-dev_7.21.0-2.1+squeeze5_amd64.deb d753d6b27f6e2af416e1ce8a4aabb91a69c6f26d 106850 libcurl3-dbg_7.21.0-2.1+squeeze5_amd64.deb Checksums-Sha256: 4defb53d7e2c0e449d932699c1ec0212f2c17f51e34c10580f9c9feca06f6172 2168 curl_7.21.0-2.1+squeeze5.dsc da569b740edcf1a69bcdc88b2dc442f26f7347b2e1e78370761c2482f749c183 102344 curl_7.21.0-2.1+squeeze5.debian.tar.gz 4e0b83da3a0900daa45c264d576caefd39aa5aa101ac7d4b6bc862d5dcfff712 229292 curl_7.21.0-2.1+squeeze5_amd64.deb 327eaf72cb7189dac7b97d34b47847f510844c4ab0a043a90a4a77e8c3efbe77 285296 libcurl3_7.21.0-2.1+squeeze5_amd64.deb b6692e73811bc367a9f8a7fd9af4b7820d00df77e690c5b92d8410c32ca5ad2b 266244 libcurl3-gnutls_7.21.0-2.1+squeeze5_amd64.deb 462264c53865f693e7a8b85a8c4b8380b3fdb5451d5271e034551a01ee01fbcf 1100160 libcurl4-openssl-dev_7.21.0-2.1+squeeze5_amd64.deb dc3d7d723d948eb223984081589a15547130978cd31265fff289fa8e279a912d 1075850 libcurl4-gnutls-dev_7.21.0-2.1+squeeze5_amd64.deb 385bea343c85e40a23f17d5b703fbfb3b83ddccc71fe4936773d1fdb57a23d50 106850 libcurl3-dbg_7.21.0-2.1+squeeze5_amd64.deb Files: 5ffab2f670dc4c820d583bb3dc73324e 2168 web optional curl_7.21.0-2.1+squeeze5.dsc 4d92b15227ce26ca93a7a5cc911806c9 102344 web optional curl_7.21.0-2.1+squeeze5.debian.tar.gz 74415613153c82bd3cdb666ef27cfd2f 229292 web optional curl_7.21.0-2.1+squeeze5_amd64.deb 8b11a4b2b9f2ad052334d4c4cc0ca84a 285296 libs optional libcurl3_7.21.0-2.1+squeeze5_amd64.deb e1c4eb110536d4ad3fcd06aa52dc5eef 266244 libs optional libcurl3-gnutls_7.21.0-2.1+squeeze5_amd64.deb f03292dc0fb909b0cd5bc783ca65bfbe 1100160 libdevel optional libcurl4-openssl-dev_7.21.0-2.1+squeeze5_amd64.deb 48a1a3efa03f130db1fd2677b0b370c0 1075850 libdevel optional libcurl4-gnutls-dev_7.21.0-2.1+squeeze5_amd64.deb a88b52ff81c72361ea787c657373b436 106850 debug extra libcurl3-dbg_7.21.0-2.1+squeeze5_amd64.deb -----BEGIN PGP SIGNATURE----- Version: GnuPG v1.4.15 (GNU/Linux) iQIcBAEBAgAGBQJSh2SxAAoJEK+lG9bN5XPLbAMQAJGG5qp0vA3Lef6ejFWwE9H+ Z5uecO3+jQndx/Y3X2pR/C2t7U98CCgFWThP4lSFm9gvJlARTc4/4XU5fWaHUHKF z+Btne9mvQkPs3vuJMqGrGfJCHCJtgq0dIHT0ljjMIvuut2/dhC1Cm9zwBvYs5uB jij/mE4157blHxq6OBzVcAK97zkq+rWslxi0bvT8xtG++t6x40lWJ7xxyelWugQF 0M+OOJQatg3Xc8ZdcNzQMF9dfWIKcePpKgN3dYD6gu4/njmKpzeXqqVPY/3NUWql 6oN9D6riCAQ2OgvDH/aYwkKRI3HiFL+VRJ0M01Y/GyZ9AVjQgqXuHRzcx0/OO3fc WiLaPsFSlVV56GqFDAy5yCxsLom6k95uwUYZFIHzY1W1A43HbRpZZ1VkMeCgt287 TfJ0VVziD6gzne2MOOd9CUyvjDGYmQT6qfFcZS7cd8SD65/KeM+QDdiLvQtO8BtR XfkOYcyYJnJT27ZyK+FyQ9XVE+2D24LrEaz0O5KztuK3HUw+A2kERZuppxhMfkS/ Pt76OPJDKZPH594nwk3WocmBU4Z6Q7HJTrmCbnVwuClPTECgvH/nSnwDk6k8LlFF aszevWaBL2bVnWiGYFL0fQ216rAiWqJ2NuvJQGH+GZbvcJeTwLWPvUkhPNYaNjHI bOQzO2s7+oipBYQSd/Rm =Qgp+ -----END PGP SIGNATURE-----