-----BEGIN PGP SIGNED MESSAGE----- Hash: SHA1 Format: 1.8 Date: Wed, 11 Dec 2013 18:00:59 +0100 Source: curl Binary: curl libcurl3 libcurl3-gnutls libcurl3-nss libcurl4-openssl-dev libcurl4-gnutls-dev libcurl4-nss-dev libcurl3-dbg Architecture: source amd64 Version: 7.26.0-1+wheezy7 Distribution: stable-security Urgency: high Maintainer: Alessandro Ghedini <ghedo@debian.org> Changed-By: Alessandro Ghedini <ghedo@debian.org> Description: curl - command line tool for transferring data with URL syntax libcurl3 - easy-to-use client-side URL transfer library (OpenSSL flavour) libcurl3-dbg - debugging symbols for libcurl (OpenSSL, GnuTLS and NSS flavours) libcurl3-gnutls - easy-to-use client-side URL transfer library (GnuTLS flavour) libcurl3-nss - easy-to-use client-side URL transfer library (NSS flavour) libcurl4-gnutls-dev - development files and documentation for libcurl (GnuTLS flavour) libcurl4-nss-dev - development files and documentation for libcurl (NSS flavour) libcurl4-openssl-dev - development files and documentation for libcurl (OpenSSL flavour) Changes: curl (7.26.0-1+wheezy7) stable-security; urgency=high . * Fix GnuTLS checking of a certificate CN or SAN name field when the digital signature verification is turned off as per CVE-2013-6422 http://curl.haxx.se/docs/adv_20131217.html * Set urgency=high accordingly Checksums-Sha1: 387d8e559bd5a227ce7b8600fa456b53919528ca 2531 curl_7.26.0-1+wheezy7.dsc ec096dd859109924c3880cbc22e8b031a4c28b54 33183 curl_7.26.0-1+wheezy7.debian.tar.gz 7a18bf58ebf3a55757762c4233d3075d14c09a9e 269408 curl_7.26.0-1+wheezy7_amd64.deb e312ed5ed384132b95d286fcc24ed10db1602b6a 330342 libcurl3_7.26.0-1+wheezy7_amd64.deb af6063234a1649b0865b52cbd7b51bbf7a6e1a5f 321054 libcurl3-gnutls_7.26.0-1+wheezy7_amd64.deb 9e4c5dc0d8bb434944ec0d0a5169a20665bed68d 327780 libcurl3-nss_7.26.0-1+wheezy7_amd64.deb 989d12e82264561e53993c8a1069df01086a63e8 1271708 libcurl4-openssl-dev_7.26.0-1+wheezy7_amd64.deb 6657437ccd5a3eef25ce070ff36d0a834e6cd580 1260148 libcurl4-gnutls-dev_7.26.0-1+wheezy7_amd64.deb bb812d8e5d326187d58ee6a0565bb1ac095ef609 1267950 libcurl4-nss-dev_7.26.0-1+wheezy7_amd64.deb 09277148217bcecf70c8aebfb31a21ceafcaf4fb 3295736 libcurl3-dbg_7.26.0-1+wheezy7_amd64.deb Checksums-Sha256: fbf0404334f4905f44c78b2668a2551c716adfe5170ee707ee6eec39346feeb8 2531 curl_7.26.0-1+wheezy7.dsc e701debfa0be57432d15a0894d42b5cf410a018c4c89b2b79404fcd262fa0e38 33183 curl_7.26.0-1+wheezy7.debian.tar.gz 1f175ba22c2e7d79403deaf169c8c60b2ca1aafc4d2e8f56d9e917b85fc2c239 269408 curl_7.26.0-1+wheezy7_amd64.deb 3ef172e400d5c79ba94cec111e094957131cea3fbba9a6ef96e2c8bc8f49e3d0 330342 libcurl3_7.26.0-1+wheezy7_amd64.deb 46212e51a8c6027c819f13abb6494c32538c9b4f7951621a1a579669eb7994f5 321054 libcurl3-gnutls_7.26.0-1+wheezy7_amd64.deb 02ff6d83159694f1863f615d94ce8eaef20a3daea8e95a7ba3f32f3ed33bdfd8 327780 libcurl3-nss_7.26.0-1+wheezy7_amd64.deb 714a334ae0b18ac26f2ed39f5f7d72f12f6303de269626a77a4e4b7e69845adb 1271708 libcurl4-openssl-dev_7.26.0-1+wheezy7_amd64.deb 291024c98a952a06950ddd9d18f116e06367890dbc714a4697c6c04b98362362 1260148 libcurl4-gnutls-dev_7.26.0-1+wheezy7_amd64.deb 2d5534cebb964f8024f34074ab2f680b4333ced04f1dc220cb13e9118b072645 1267950 libcurl4-nss-dev_7.26.0-1+wheezy7_amd64.deb 4f9090f957e838bdb51ac64ef8b81ff764aa15b175e2730b4b124474e597314b 3295736 libcurl3-dbg_7.26.0-1+wheezy7_amd64.deb Files: 65e613368355e937e4b9134c413cd6ea 2531 web optional curl_7.26.0-1+wheezy7.dsc 64f54da113c74d324176570ede74b504 33183 web optional curl_7.26.0-1+wheezy7.debian.tar.gz 7c3f40caf20f31f042313a2cd1ddc312 269408 web optional curl_7.26.0-1+wheezy7_amd64.deb d45ea0ca598d5bd337ff9ddc47a0f07f 330342 libs optional libcurl3_7.26.0-1+wheezy7_amd64.deb 3c1b72cc69f156c56444093404c6c56e 321054 libs optional libcurl3-gnutls_7.26.0-1+wheezy7_amd64.deb bd6896926ca9124dba7a1f5c06d2c931 327780 libs optional libcurl3-nss_7.26.0-1+wheezy7_amd64.deb 16da80ddee8d88245795c05e24b96298 1271708 libdevel optional libcurl4-openssl-dev_7.26.0-1+wheezy7_amd64.deb b7ce697d5d6ad2079ff902cb0662691c 1260148 libdevel optional libcurl4-gnutls-dev_7.26.0-1+wheezy7_amd64.deb 3d7ed7e49bee96dcbfff641590ce5ff7 1267950 libdevel optional libcurl4-nss-dev_7.26.0-1+wheezy7_amd64.deb a8ce274ef155ba4c01419b1c17c486c4 3295736 debug extra libcurl3-dbg_7.26.0-1+wheezy7_amd64.deb -----BEGIN PGP SIGNATURE----- Version: GnuPG v1.4.15 (GNU/Linux) iQIcBAEBAgAGBQJSshIaAAoJEK+lG9bN5XPL4pwQAJY4vSY0ZlbOBXYOmapWCu8w gpWikM5B5z8q3G88Jr1qY9ucn8cB294YeDl1tdXwEKATbz7X7ZUnUlaRG3CzrvNQ MVsTz2W/DNFmR2GKLDST7uesXUfjlZueUjWb+IfSVsUXsP/ed0IGYsGfdxhi+x/f 19EemVYI5aWdp2U/XT6t7oQ5f45XeD/Nx7ZbmVCvyPPZFViNnvE0Gx+c9KXT07j4 /xmB6PEhCUudLGRLqh1iIqiVQB7uHQbu7GaJFLDdi2z4OPS57+Z2RcDL16V5ydD1 9eHvEaaUFrRS5PrgoWu3KJyF4LJGn1hDbLPyPoRh5cy/PpJKYNU1vyU6ra3suyVm 4khoBQNzw4wBCX2M70ozlkDTzrcj/Dj2TOzxyShSabYptI3ebQVu9QwJkFjK9WEB EMV8wDinmR2EQZwplccGUjF1OlWnQ5gbCtm9atQrO0TElY1EaBC93z/pn8E9HzOI mzv5pjL4Y3oKk5sKVBzmXguvygiQ79NkV+FDazCezROtdEkH3s3psxhU3yt4qIAO NS4CWPXsbFlxRAI94gHn3faAUNGJodb1GVfOQ3taqm782rrT9H8DsPB76W2WbMQ9 CNGYbuw5yoWppw1ywPYQ3qFw6kR8AEJ8pru5+0TKgpR0mxgzI5JrVg7X8S6Y3vcv UvvcqMskNc6/RwDuSxBW =p8K4 -----END PGP SIGNATURE-----