-----BEGIN PGP SIGNED MESSAGE----- Hash: SHA1 Format: 1.8 Date: Fri, 26 Sep 2014 18:07:38 +0200 Source: curl Binary: curl libcurl3 libcurl3-gnutls libcurl4-openssl-dev libcurl4-gnutls-dev libcurl3-dbg Architecture: source i386 Version: 7.21.0-2.1+squeeze9 Distribution: squeeze-lts Urgency: high Maintainer: Ramakrishnan Muthukrishnan <rkrishnan@debian.org> Changed-By: Thorsten Alteholz <debian@alteholz.de> Description: curl - Get a file from an HTTP, HTTPS or FTP server libcurl3 - Multi-protocol file transfer library (OpenSSL) libcurl3-dbg - libcurl compiled with debug symbols libcurl3-gnutls - Multi-protocol file transfer library (GnuTLS) libcurl4-gnutls-dev - Development files and documentation for libcurl (GnuTLS) libcurl4-openssl-dev - Development files and documentation for libcurl (OpenSSL) Changes: curl (7.21.0-2.1+squeeze9) squeeze-lts; urgency=high . * Non-maintainer upload by the Squeeze LTS Team. * Fix security issue: - Only use full host matches for hosts used as IP address as per CVE-2014-3613 * This patch is applied to Wheezy but not really needed, so it is omitted here (needed for version > 7.38) - Reject incoming cookies set for TLDs as per CVE-2014-3620 Checksums-Sha1: e6ce4d5cd0a14c337539ee32c9f5bf748e5f7f32 1513 curl_7.21.0-2.1+squeeze9.dsc d0e5a1184315b9abb9cc54d77d4a0200526f046d 2714501 curl_7.21.0.orig.tar.gz 223ccd9668ffc095503d1df9fd389a27a46d93bb 106168 curl_7.21.0-2.1+squeeze9.debian.tar.gz aeb2f4b3211fd81ada0df6245c87d6ba2d6b1490 228288 curl_7.21.0-2.1+squeeze9_i386.deb 2c0f8d5fc9db0b276d9d2d8c23f78d9fc16dc797 281640 libcurl3_7.21.0-2.1+squeeze9_i386.deb c7e712c585a447b36257af150bddca5e134ff18b 261338 libcurl3-gnutls_7.21.0-2.1+squeeze9_i386.deb ff3f13e35285e543d28f35cc7ad763febfcb58e2 1060916 libcurl4-openssl-dev_7.21.0-2.1+squeeze9_i386.deb 15a90f1fdd997015792da19f08d8538d716e840c 1039826 libcurl4-gnutls-dev_7.21.0-2.1+squeeze9_i386.deb a10d4e83b34f47c60d9eb3f4127d9647b7e71762 112202 libcurl3-dbg_7.21.0-2.1+squeeze9_i386.deb Checksums-Sha256: 4df7d3de499879524d0c5505314390ffd49ddef028694dd0e541b39e5529ffc3 1513 curl_7.21.0-2.1+squeeze9.dsc b3e2047c6f70eb321557af980a9554f0a98fb122d9636f1c98833262eed8de1d 2714501 curl_7.21.0.orig.tar.gz bcc149e75cdaa2aa141d60c76e8e19c1ce345019961acfde198eb1e8309e4627 106168 curl_7.21.0-2.1+squeeze9.debian.tar.gz 4d0f29395394d3f2e012528bbcff5050709e0fb061ce1ee6fbd974b51f47fcb7 228288 curl_7.21.0-2.1+squeeze9_i386.deb 6bc1545044147ee422987e422195bda983b0a3d1dec77a8dc5328685be78eef1 281640 libcurl3_7.21.0-2.1+squeeze9_i386.deb b9ac7f46314f45e5e388f01f1e731751e430d0a5d237ef4799a3b7fca8764b6b 261338 libcurl3-gnutls_7.21.0-2.1+squeeze9_i386.deb 01064a88596b32eee7dff0428dedf75382b1a38da248bf2388e1abd5c3f079d3 1060916 libcurl4-openssl-dev_7.21.0-2.1+squeeze9_i386.deb 2117546dc7a082a00fdf2c8f74c511ce6c2209fdef148dccc1e998ed404d5fcd 1039826 libcurl4-gnutls-dev_7.21.0-2.1+squeeze9_i386.deb c9d7dc5bf05205cdb4e9a0b4d74e0ebd7e084ff423f2f7b1bc3b48e9e427aa23 112202 libcurl3-dbg_7.21.0-2.1+squeeze9_i386.deb Files: 34a788ce435d014e5b749a60ee245734 1513 web optional curl_7.21.0-2.1+squeeze9.dsc 6dfb911a254a1b5ca8b534b98f2196aa 2714501 web optional curl_7.21.0.orig.tar.gz 64eeb394e90138e57ebcd871383f9b11 106168 web optional curl_7.21.0-2.1+squeeze9.debian.tar.gz b1ba336074647b8f1d75566b34fa4802 228288 web optional curl_7.21.0-2.1+squeeze9_i386.deb f382bc647b9f67474800baad1a7bee1d 281640 libs optional libcurl3_7.21.0-2.1+squeeze9_i386.deb 81541e5848a77f47ab6fb0fc91dd37fd 261338 libs optional libcurl3-gnutls_7.21.0-2.1+squeeze9_i386.deb 15c715bfd37907911a92728dec62cc09 1060916 libdevel optional libcurl4-openssl-dev_7.21.0-2.1+squeeze9_i386.deb 596b9288bfb5881c0bdc2ba799f07c24 1039826 libdevel optional libcurl4-gnutls-dev_7.21.0-2.1+squeeze9_i386.deb 5795d94bf567df14a51129342ca16f85 112202 debug extra libcurl3-dbg_7.21.0-2.1+squeeze9_i386.deb -----BEGIN PGP SIGNATURE----- Version: GnuPG v1 iEYEARECAAYFAlQl1DIACgkQ02K2KlS5mJAMEACeJOmFOVqje3LQ+nvODgJf1Etg LWgAn0C79fNsXajjd3onBzE77vy0oBrS =dbHB -----END PGP SIGNATURE----- -- To UNSUBSCRIBE, email to debian-lts-changes-request@lists.debian.org with a subject of "unsubscribe". Trouble? Contact listmaster@lists.debian.org Archive: https://lists.debian.org/E1XXcvp-0007FD-Sp@franck.debian.org