-----BEGIN PGP SIGNED MESSAGE----- Hash: SHA512 Format: 1.8 Date: Thu, 12 Dec 2024 21:38:04 +0000 Source: curl Architecture: source Version: 8.11.1-1 Distribution: unstable Urgency: medium Maintainer: Debian Curl Maintainers <team+curl@tracker.debian.org> Changed-By: Samuel Henrique <samueloph@debian.org> Closes: 1089682 Changes: curl (8.11.1-1) unstable; urgency=medium . [ Samuel Henrique ] * New upstream version 8.11.1 - Fix CVE-2024-11053: netrc and redirect credential leak (closes: #1089682) * Update wcurl to 2024.12.08 * New patches: - async_thread_avoid_closing_eventfd_twice: Fix file descriptor issue with eventfd - sectransp_free_certificate_on_error: Fix memory leak * Refresh patches: - ZZZgnutls-build - build-Divide-mit-krb5-gssapi-link-flags-between-LDFLAGS-a * d/p/11_omit-directories-from-config: Update patch * Drop merged patches: - cmdline_ech_md_formatting_cleanups - duphandle_also_init_netrc - libssh_when_using_IPv6_numerical_address_add_brackets - netrc_support_large_file_longer_lines_longer_tokens - setopt_fix_CURLOPT_HTTP_CONTENT_DECODING * d/p/Remove-curl-s-LDFLAGS-from-curl-config-static-libs: Remove patch, not needed anymore . [ Carlos Henrique Lima Melara ] * d/t/upstream-tests-*: test gnutls backend against installed curl * d/t/control: install curl on upstream-tests-gnutls and remove on openssl Checksums-Sha1: bfa349b707ecaa6b53fb4fbd1e4fe69d66dae28d 3252 curl_8.11.1-1.dsc 785a854854ea2f80754d6cfbf7e3074a3d04710c 4169067 curl_8.11.1.orig.tar.gz 70366b9763c7be0134b75b3cfc1bf373007d7a21 484 curl_8.11.1.orig.tar.gz.asc 699686c7f746db234aab28f336e73aa5bb2e925e 53972 curl_8.11.1-1.debian.tar.xz 8d586bdccbf616d2e80483997343555990714fa1 12210 curl_8.11.1-1_amd64.buildinfo Checksums-Sha256: 6611dcd0c91d6dc8b4363b8a4472812a3044a04cba2304c64a0d1c6d06d91069 3252 curl_8.11.1-1.dsc a889ac9dbba3644271bd9d1302b5c22a088893719b72be3487bc3d401e5c4e80 4169067 curl_8.11.1.orig.tar.gz d6c44df0a8e6958ef8d38fceda44f219db666b8215da6b33dc7dda81fcfc696b 484 curl_8.11.1.orig.tar.gz.asc 511130b8192911c22e03832a005531dd8990d9f5821640b6bac12a750d54bf33 53972 curl_8.11.1-1.debian.tar.xz b95e784dd85f1ce83a47a9eab09eaa1c586b8f9bf87049f7aa1f5360196139b0 12210 curl_8.11.1-1_amd64.buildinfo Files: ad7697ee4cba63cb4e76bf45988b9cc7 3252 web optional curl_8.11.1-1.dsc 8eed752aeeb8ee54063b75baf95d3e14 4169067 web optional curl_8.11.1.orig.tar.gz 6ef30ecafd1513f1d3cef9fd5f6508b9 484 web optional curl_8.11.1.orig.tar.gz.asc c077fb6e6b63c28c79d661e15ab5685d 53972 web optional curl_8.11.1-1.debian.tar.xz dee116f8351b5121f2ddd860f8a9f376 12210 web optional curl_8.11.1-1_amd64.buildinfo -----BEGIN PGP SIGNATURE----- iQIzBAEBCgAdFiEEBdtqg34QX0sdAsVfu6n6rcz7RwcFAmdbW2UACgkQu6n6rcz7 Rwdj/A//X2BovVlcpANMhmONG7swpl2X1TCyooZ6dl4K780wcBWlXMzmT229aGCm Dkl1vNUXKwueJvV2LU3SAfRlXWh5i+xxq/P0E3eLdTZmseJ5a5AKanDrGXaZPOdm VUsyz7tfzBU1q+y7aXLsiRnjsv6fGDsJTNIlt08s48K5+HIR0qFvhZFVkda1cLl3 3YcyH6J1+LIFpTJTQ9pEL5t7pJj7R6E54iqmY9K8bZ+0tLYuuDaX+yh6T13g4V62 GheLRJXiS1kDUEObEqNGu8/IrYYLFnnyY4WhiDDM3TdA/m/d0NMNrwt20M0bgpwi NGXJAvZjSyZafMSreAquS0rEXsWCPeUodh3sQ+jhs5NR+WIxTqzjEDnuKoDY6vXF j79dnwhNELVa4jLtqo/MLVPEO827y40ohiRaXm4dCKJ1JG/oodg9UDSHTA7dO2m7 JvsFsTiEyl/QUAOVSsPW3U5F1oDcmRuXAezCf68R5CiYmS38vJsPJnGXfoyoyWdo U3IfUNoYqBeTxesudNnkkYGCov7Wn1l/2OE2ewcTuNhckqYT6XPCORE/sEPMW1Vk r0DQSPIkSbybp7auR0Vw34o/IJo5RAr0tH8ZtgFniv8YGwHBV+55k/RIgwLpufr1 +dJJvmuiIFpGi/jLPFXJ83AUT22JHVCuQGLGKTGqdk+vSq9++pU= =y1jg -----END PGP SIGNATURE-----