-----BEGIN PGP SIGNED MESSAGE----- Hash: SHA1 Format: 1.8 Date: Wed, 10 Sep 2014 20:11:02 +0200 Source: curl Binary: curl libcurl3 libcurl3-gnutls libcurl3-nss libcurl4-openssl-dev libcurl4-gnutls-dev libcurl4-nss-dev libcurl3-dbg libcurl4-doc Architecture: source amd64 all Version: 7.38.0-1 Distribution: unstable Urgency: medium Maintainer: Alessandro Ghedini <ghedo@debian.org> Changed-By: Alessandro Ghedini <ghedo@debian.org> Description: curl - command line tool for transferring data with URL syntax libcurl3 - easy-to-use client-side URL transfer library (OpenSSL flavour) libcurl3-dbg - debugging symbols for libcurl (OpenSSL, GnuTLS and NSS flavours) libcurl3-gnutls - easy-to-use client-side URL transfer library (GnuTLS flavour) libcurl3-nss - easy-to-use client-side URL transfer library (NSS flavour) libcurl4-doc - documentation for libcurl libcurl4-gnutls-dev - development files and documentation for libcurl (GnuTLS flavour) libcurl4-nss-dev - development files and documentation for libcurl (NSS flavour) libcurl4-openssl-dev - development files and documentation for libcurl (OpenSSL flavour) Changes: curl (7.38.0-1) unstable; urgency=medium . * New upstream release - Only use full host matches for hosts used as IP address as per CVE-2014-3613 http://curl.haxx.se/docs/adv_20140910A.html - Reject incoming cookies set for TLDs as per CVE-2014-3620 http://curl.haxx.se/docs/adv_20140910B.html * Drop 08_link-curl-to-nss.patch (merged upstream) * Refresh patches * Fix wildcard-matches-nothing-in-dep5-copyright * Add 08_fix-spelling.patch Checksums-Sha1: 2c3d4817e34047e30ae6925547fe51bba50f07ea 2625 curl_7.38.0-1.dsc 40d8ec9063f076005535139c9229ac77c57f0300 4094034 curl_7.38.0.orig.tar.gz 395794f6e2f00928d89b1cc923e07281c5061ae5 25156 curl_7.38.0-1.debian.tar.xz b3bc2cd7b49d24ab7ca9b650152cb77c7fac1e78 197052 curl_7.38.0-1_amd64.deb 58834cdb0ce512f347dfedd1b844b3cf02015e89 257602 libcurl3_7.38.0-1_amd64.deb 022da4154bf8a89cc55a8994a0743c854f66e71e 249852 libcurl3-gnutls_7.38.0-1_amd64.deb 5ff153b7709157febce0fa555976b706d42b07a6 261236 libcurl3-nss_7.38.0-1_amd64.deb bcf0ef662932076318eab2a3704c6a41f23f687e 334804 libcurl4-openssl-dev_7.38.0-1_amd64.deb bd53fc664203e5df983bd8e6f9b104a603f53244 326116 libcurl4-gnutls-dev_7.38.0-1_amd64.deb 18ce55247b17b13bc232f1fc78a9566bfe35f7ce 338826 libcurl4-nss-dev_7.38.0-1_amd64.deb 9483a91e96081ee7611bb987fce654416ed940e7 3357862 libcurl3-dbg_7.38.0-1_amd64.deb 983db8acb5e9bbf95e593b334f90f5b8356fd217 1066560 libcurl4-doc_7.38.0-1_all.deb Checksums-Sha256: 7956744f47eb60a4c0e54e61836a9303365b9d90d744ad39ff438b1f0c47b8de 2625 curl_7.38.0-1.dsc 5661028aa6532882fa228cd23c99ddbb8b87643dbb1a7ea55c068d34a943dff1 4094034 curl_7.38.0.orig.tar.gz 037c6cc4804da6cf526abb4ec60a383865368568264638ac3b9a84b44ce1fb44 25156 curl_7.38.0-1.debian.tar.xz 78de5d1c5008ed9a90a6bd5aeea6828696894e7f19c4d36afebbf233f178a137 197052 curl_7.38.0-1_amd64.deb 9a435f7dab5d37dfac9c71bc8052b090247e8a696eb201c940dfd6e628fe6768 257602 libcurl3_7.38.0-1_amd64.deb 06d35b0ebe0fa856bcd329559bf7ff966a891da5f86aa2a2fa53cb9220c15585 249852 libcurl3-gnutls_7.38.0-1_amd64.deb 6ee6b6f1bef60a85345ada9235acd4b497d59cc91d81e1adc55fdea49020c3dd 261236 libcurl3-nss_7.38.0-1_amd64.deb 708615bb3647c7971cc09a3d0876351e86a6a0a6e0ce90b14eb31e0b35822bec 334804 libcurl4-openssl-dev_7.38.0-1_amd64.deb afdb38360fbe1e389473c5308ec0e79beab22641a89767d08bbfe1de11d3c37a 326116 libcurl4-gnutls-dev_7.38.0-1_amd64.deb dc6dcdc66f6d0de3151a86a070cdca932716ff9d17c418e37f35278026b8d23f 338826 libcurl4-nss-dev_7.38.0-1_amd64.deb a7412a83a626a3c3bbd9c6b3a3203572face2e3d8874fdfcdadf94e76133059e 3357862 libcurl3-dbg_7.38.0-1_amd64.deb 4f718847959406a65c0d323fead28d7f193607159f2c15ca178ea65f2495145e 1066560 libcurl4-doc_7.38.0-1_all.deb Files: 217cb5f117ad4c2365d7f456b2fdf585 197052 web optional curl_7.38.0-1_amd64.deb 3447c65d09c3fdea5990291353f7aa49 257602 libs optional libcurl3_7.38.0-1_amd64.deb 9c80468580903e283158dc80c44bbb02 249852 libs optional libcurl3-gnutls_7.38.0-1_amd64.deb 49f3c34db95182e4b77344cd12553cc8 261236 libs optional libcurl3-nss_7.38.0-1_amd64.deb 08770ab4dad741799b2d64da9288b535 334804 libdevel optional libcurl4-openssl-dev_7.38.0-1_amd64.deb 900992ffafa06937ebecab59ec68923f 326116 libdevel optional libcurl4-gnutls-dev_7.38.0-1_amd64.deb 867b0413ebff6a8db89a50ad116cdeb1 338826 libdevel optional libcurl4-nss-dev_7.38.0-1_amd64.deb de64be28275f826ac229d44bb1e856ad 3357862 debug extra libcurl3-dbg_7.38.0-1_amd64.deb c0559541a54ad9843a09a6d9f2eaf60f 1066560 doc optional libcurl4-doc_7.38.0-1_all.deb 1ccf0df761894f76262f391168c74f85 2625 web optional curl_7.38.0-1.dsc b6e3ea55bb718f2270489581efa50a8a 4094034 web optional curl_7.38.0.orig.tar.gz a323af6538c4f6a5b7a64359755e82ca 25156 web optional curl_7.38.0-1.debian.tar.xz -----BEGIN PGP SIGNATURE----- Version: GnuPG v1 iQIcBAEBAgAGBQJUEJq/AAoJEK+lG9bN5XPL2G0QAICXi5oUe2rbrupxCDD8Nc9K nMdliWdyqw0K16tGTQzQXkq0i5Tpg1qELjQpO3Lcp+r5+ESNvnrQnhHScpfOPK9b U68qp6S2Gw5bkjCKgB5mbSiHno1nlEWLKJYeyi2uRsPKeilQqSJ77ntHD5lixcJM tG9ApPRgO8zGV/mc6t8OQxfIFZzISBT/ZeMZGnOtdc1//mgHUaApFGQiR63E42Fl leodzYAhcvT00scZQj3yfMYTAFe8aXNkoElF2Z4SpKikQffV/Nd3wMlsC3zULHH+ 5XyyQFbmp4jCfiWbHQvQ2kYXLgU5EpgU1i4eb6MTycN1+gQ2VabrLVoOQZ4mGQrP zx1AeihDhvvVV3GgGj3d7oYNTlgrG+OlJ03mVnSpAb+1gfUe/wz8dQuNzDFhc5MW 893VtjQQG37dO2wqWuBBFAlSnWiS4z/qQ7Zrkx9XGKN39m/fDTA65Utsq5HGLttU ggGQVCY2QvUqvRZNqs92n2mlIeAsvRbQkYT1sjgi9QHRmk0gVVPuE8NeB42VFQ/l tPf1wa2vqO4y/k57gcFkh2sJXM4146C81pNERs768DptvTjpmV22dw2ViOnpitmR JE48VDejxPW9LMNvhR43jM/RjKJGPx0ogWg5zXwO3q/Wr/90bLUwQgpWha0Gnk5l AGadMPDjvwcLXbVMF8EI =I3Ko -----END PGP SIGNATURE-----