-----BEGIN PGP SIGNED MESSAGE----- Hash: SHA1 Format: 1.8 Date: Sat, 06 Sep 2014 14:07:02 +0200 Source: curl Binary: curl libcurl3 libcurl3-gnutls libcurl3-nss libcurl4-openssl-dev libcurl4-gnutls-dev libcurl4-nss-dev libcurl3-dbg Architecture: source amd64 Version: 7.26.0-1+wheezy10 Distribution: wheezy-security Urgency: high Maintainer: Alessandro Ghedini <ghedo@debian.org> Changed-By: Alessandro Ghedini <ghedo@debian.org> Description: curl - command line tool for transferring data with URL syntax libcurl3 - easy-to-use client-side URL transfer library (OpenSSL flavour) libcurl3-dbg - debugging symbols for libcurl (OpenSSL, GnuTLS and NSS flavours) libcurl3-gnutls - easy-to-use client-side URL transfer library (GnuTLS flavour) libcurl3-nss - easy-to-use client-side URL transfer library (NSS flavour) libcurl4-gnutls-dev - development files and documentation for libcurl (GnuTLS flavour) libcurl4-nss-dev - development files and documentation for libcurl (NSS flavour) libcurl4-openssl-dev - development files and documentation for libcurl (OpenSSL flavour) Changes: curl (7.26.0-1+wheezy10) wheezy-security; urgency=high . * Fix multiple security issues: - Only use full host matches for hosts used as IP address as per CVE-2014-3613 - Reject incoming cookies set for TLDs as per CVE-2014-3620 * Set urgency=high accordingly Checksums-Sha1: 248b3caf360d0db709362cdb796459dc7021278e 2518 curl_7.26.0-1+wheezy10.dsc 906c9e1ac5caebb4b365b2b290f6757a3eb33cc1 37222 curl_7.26.0-1+wheezy10.debian.tar.gz 314851594a5db210c88995f00395c453af0317e3 269614 curl_7.26.0-1+wheezy10_amd64.deb 41e5c37d1838ceb8770a9d26439964f459551e8f 330842 libcurl3_7.26.0-1+wheezy10_amd64.deb 84c72df47267f3f4e16436ffb1700be438f73a49 321522 libcurl3-gnutls_7.26.0-1+wheezy10_amd64.deb c22650340e8a1448dc3e96fe73915f48a2434597 328226 libcurl3-nss_7.26.0-1+wheezy10_amd64.deb c6151806d360a7fc797918b5376f995df1464055 1272252 libcurl4-openssl-dev_7.26.0-1+wheezy10_amd64.deb 1f5e765ddc0a054bd9a6bb3571719abe9c2ef1b2 1260678 libcurl4-gnutls-dev_7.26.0-1+wheezy10_amd64.deb 0f4695e9bb49e9502336850ea4f4030a656f2053 1268492 libcurl4-nss-dev_7.26.0-1+wheezy10_amd64.deb 1d7cc9a48cb3c0554628a75b0b198df853a9971b 3299958 libcurl3-dbg_7.26.0-1+wheezy10_amd64.deb Checksums-Sha256: 3f71bd7c140dbf43cebdc0b132eb9a70389602fb8ca3baf385a4b0590de30302 2518 curl_7.26.0-1+wheezy10.dsc e62e1100d9e2c425a980e582b96469aa2aaca9b90544471fdf7c621bf2758575 37222 curl_7.26.0-1+wheezy10.debian.tar.gz a48b33b182552957ec096bc591ee4b2ac90fb095aa723f8dd62c1789c2cbef00 269614 curl_7.26.0-1+wheezy10_amd64.deb 86b813e1d28a44cb2cc3335a5fc71d00eb2cb3718ac8ee60acf9a590ed95eb9a 330842 libcurl3_7.26.0-1+wheezy10_amd64.deb f616070744dd4a109426f58be3a10678e8c5cd914c9b700cb4ca23eb5be7c748 321522 libcurl3-gnutls_7.26.0-1+wheezy10_amd64.deb d615e31735498478b3fee922003b80e066808b3c7ec4e24808ce21ec1aba9705 328226 libcurl3-nss_7.26.0-1+wheezy10_amd64.deb 2da4c0629c3b59f100aeb195f6df03623a802ec7519d164fb39e46f783126c8b 1272252 libcurl4-openssl-dev_7.26.0-1+wheezy10_amd64.deb f576729f0f08fb0d06090bdc3a4aad0b097862391b20affbdace777892dfcfd4 1260678 libcurl4-gnutls-dev_7.26.0-1+wheezy10_amd64.deb 9f7bd5bc6fcbbe72b40d07efb9dc1a4a98fb51240aed2fbbbe9c57560a6647cf 1268492 libcurl4-nss-dev_7.26.0-1+wheezy10_amd64.deb c05afd4017b371d86d865e1331a563adbd371fa9d6ef2f5e4b6ecb0a991456a4 3299958 libcurl3-dbg_7.26.0-1+wheezy10_amd64.deb Files: 81e96a8508075e2938bf0dee3e8cff5c 2518 web optional curl_7.26.0-1+wheezy10.dsc 5b2de032c65c109854d33113d3030465 37222 web optional curl_7.26.0-1+wheezy10.debian.tar.gz ed509ccf64062ecc4a9ab66d8d405f33 269614 web optional curl_7.26.0-1+wheezy10_amd64.deb 42a9eae06d9337cbf12821a3d042810f 330842 libs optional libcurl3_7.26.0-1+wheezy10_amd64.deb a405425f48415d32361d14fa2207e008 321522 libs optional libcurl3-gnutls_7.26.0-1+wheezy10_amd64.deb df9d165f6dd54875a707d1dc5527bdb1 328226 libs optional libcurl3-nss_7.26.0-1+wheezy10_amd64.deb ed5a297015ac8e40a4c434c91aa3b6da 1272252 libdevel optional libcurl4-openssl-dev_7.26.0-1+wheezy10_amd64.deb 5f1af82ce040884bc1483ec30d646163 1260678 libdevel optional libcurl4-gnutls-dev_7.26.0-1+wheezy10_amd64.deb 806304c84d3cb13ed7d8f6e685e57a72 1268492 libdevel optional libcurl4-nss-dev_7.26.0-1+wheezy10_amd64.deb 27aa50e5b34a5e66e8a7abbf4de0edaf 3299958 debug extra libcurl3-dbg_7.26.0-1+wheezy10_amd64.deb -----BEGIN PGP SIGNATURE----- Version: GnuPG v1 iQIcBAEBAgAGBQJUCv+tAAoJEK+lG9bN5XPLfV4P/R/URR/YghWiKWVS0O4Kz+e1 xB+NgDts+oDOS07nUQkNghHUEuOVaIQBG9+g1PTgXSiRzaQxKyH1scB3t4Fo08Xz AgHlfRbibV5cX0YhPkaFaP3rTxIzrsZjUyUpJxP6I9kCP7ViC0JOV2Ua3GaowbNp x/RUyZi2nfIMYt98tECWIOcQnIeZt/e/3eOaQ0dFkzijQn6cRXr/BXnSppJ7obzq eZKyLfNslBjz+bS+3Ucjv6ezvl+pTGnczFJvy72NU41JWfybZu/7sJY0pqJ9PtIE W4dUAMn+plCDHkodkXhEi+znUytF7V9pXY8inrvIo0Bxn/ykg7qB0fEyriKQ3yy4 G8iG/xbvmml/3FBpb4mh22mLxKLV9+Djugu+UYzfHafPGn7TSloA4M0+7tFpCFlP rkYEXIxB79nJRs6uH9LAYIC187x/s6i2OYJYM0KOF/aJBaPbqXu7PFtb/BU1h+g4 CsMzgKKI/rIe+kLCfYeM1G4C5/xZO6vQxakwgqHXkIstu12jQvAS0n0+LR+bjGKj C9jz+3rAldSiUbbBCSDB0vNE4CebW65rLH+rvPT6nB1K/EQUxacLFh+0o9w8J3DS +uKEZKBnmLnkxG7i1Z2y7525SFHl/onpofPIg8jAyz2/5ZvHZ1PJDS96VIFkdCDc PsLKVJd/hABw0akczwlA =SOGl -----END PGP SIGNATURE-----