-----BEGIN PGP SIGNED MESSAGE----- Hash: SHA512 Format: 1.8 Date: Sun, 22 Oct 2017 21:23:30 +0100 Source: curl Binary: curl libcurl3 libcurl3-gnutls libcurl3-nss libcurl4-openssl-dev libcurl4-gnutls-dev libcurl4-nss-dev libcurl3-dbg libcurl4-doc Architecture: source amd64 all Version: 7.52.1-5+deb9u2 Distribution: stretch-security Urgency: medium Maintainer: Alessandro Ghedini <ghedo@debian.org> Changed-By: Alessandro Ghedini <ghedo@debian.org> Description: curl - command line tool for transferring data with URL syntax libcurl3 - easy-to-use client-side URL transfer library (OpenSSL flavour) libcurl3-dbg - debugging symbols for libcurl (OpenSSL, GnuTLS and NSS flavours) libcurl3-gnutls - easy-to-use client-side URL transfer library (GnuTLS flavour) libcurl3-nss - easy-to-use client-side URL transfer library (NSS flavour) libcurl4-doc - documentation for libcurl libcurl4-gnutls-dev - development files and documentation for libcurl (GnuTLS flavour) libcurl4-nss-dev - development files and documentation for libcurl (NSS flavour) libcurl4-openssl-dev - development files and documentation for libcurl (OpenSSL flavour) Changes: curl (7.52.1-5+deb9u2) stretch-security; urgency=medium . * Fix IMAP FETCH response out of bounds read as per CVE-2017-1000257 https://curl.haxx.se/docs/adv_20171023.html Checksums-Sha1: 1fbb2bd99a950c6dc447e4855a59d6b36b952341 2818 curl_7.52.1-5+deb9u2.dsc f5b62b8c8beff302ea796929db050bd3048a2dc9 35048 curl_7.52.1-5+deb9u2.debian.tar.xz 7a7b44b1bce54957be48a2856465a8ecf09949bf 131978 curl-dbgsym_7.52.1-5+deb9u2_amd64.deb da92fdf3f49a31191920712a1fe8dfff6d6f4e86 10800 curl_7.52.1-5+deb9u2_amd64.buildinfo 1fe13a125ba0721d1282b696db41d7b9b89d790e 227214 curl_7.52.1-5+deb9u2_amd64.deb 74b2109fb7d590bf04a1a901fca246e11512a4d1 5000426 libcurl3-dbg_7.52.1-5+deb9u2_amd64.deb 433ec8eee5043c4541d89f1a9f4ed391f6371e99 289184 libcurl3-gnutls_7.52.1-5+deb9u2_amd64.deb da8a9ba373b809559ed2ace542a4684e4f769512 294756 libcurl3-nss_7.52.1-5+deb9u2_amd64.deb 57037bfc9d73e61a9cb022d68183de5f19ac159a 291002 libcurl3_7.52.1-5+deb9u2_amd64.deb 0aa3b455cd32b857d7c8fd95ac7f8086ad19f38c 827470 libcurl4-doc_7.52.1-5+deb9u2_all.deb cf0a92683a6caec2375e8525e7fcb40c886d7268 371738 libcurl4-gnutls-dev_7.52.1-5+deb9u2_amd64.deb 97755eccbe3b84bcdb737c695f7fe33bb837c39f 377610 libcurl4-nss-dev_7.52.1-5+deb9u2_amd64.deb aa3cce802abcc2f09b9bb6a3e2a295171549d9df 373660 libcurl4-openssl-dev_7.52.1-5+deb9u2_amd64.deb Checksums-Sha256: f73c8a248b9c883064f2a6e3641810338ed4fd5e22e30e85e8d4e40427ff00bd 2818 curl_7.52.1-5+deb9u2.dsc 42d3e01db23a7d5e763f17e4d3aa32f97acfaf3154f246e3be0cbb38a1707450 35048 curl_7.52.1-5+deb9u2.debian.tar.xz aa88caa08b647f01906effbbe432733b5889a1355b86d6e3424a4d3c394f8843 131978 curl-dbgsym_7.52.1-5+deb9u2_amd64.deb da313868f13c3b4de487634ac279dec7a72b86e199a7a9062724b5cd2a0b0363 10800 curl_7.52.1-5+deb9u2_amd64.buildinfo 27f24dda5a272736efae9989e94f7f121923c5bd41035a6fdf0ed683a36c3f80 227214 curl_7.52.1-5+deb9u2_amd64.deb 485d0c89f39433fd1ba8288605f61920af6647db1bb19d61050ccf0f0a798864 5000426 libcurl3-dbg_7.52.1-5+deb9u2_amd64.deb e5da686d547f89fcf0d46988aeaacbda1077f561b4e5bc11a6eeb2611542342b 289184 libcurl3-gnutls_7.52.1-5+deb9u2_amd64.deb fa931c23d94fdc33dfa1ec5484de3025801fe0b5bd65ed8cd36c90b688eacb59 294756 libcurl3-nss_7.52.1-5+deb9u2_amd64.deb 122703f1a187ab1ce9f31c69e712a3cdd822d67ef652fe2757aae904a9d1c9c0 291002 libcurl3_7.52.1-5+deb9u2_amd64.deb efe962fdc3a79679f8f2803ee3c52efcb5e9c89c54f9b930a849b72c74c1ea9c 827470 libcurl4-doc_7.52.1-5+deb9u2_all.deb 5d018b917052ba4cd9dc1a82d369983c4ed3ce9a530d169989c55c5ef85257c9 371738 libcurl4-gnutls-dev_7.52.1-5+deb9u2_amd64.deb 804f1f2341d0add1ad40a94dc3aa1499607164b9fe39677b2cce3703ad9e9860 377610 libcurl4-nss-dev_7.52.1-5+deb9u2_amd64.deb f72f9822f0203d1768efa62fa1600bb26c82cc9a0ebddef8b61de3b83fca9b0f 373660 libcurl4-openssl-dev_7.52.1-5+deb9u2_amd64.deb Files: 74f19325e14a91249ebd0b708c627861 2818 web optional curl_7.52.1-5+deb9u2.dsc 014ed39291f757ac4e0478e91b0f7de2 35048 web optional curl_7.52.1-5+deb9u2.debian.tar.xz 1507515fa5017b610ef0a3224be05372 131978 debug extra curl-dbgsym_7.52.1-5+deb9u2_amd64.deb d7e593afab03e76228afe770346a4518 10800 web optional curl_7.52.1-5+deb9u2_amd64.buildinfo 5d4f2fd70163fc47898c8a7057182a49 227214 web optional curl_7.52.1-5+deb9u2_amd64.deb 266c05712e1a3b0364e3a05a5ca9b229 5000426 debug extra libcurl3-dbg_7.52.1-5+deb9u2_amd64.deb a39a48aeaadfd0bd5a237efb481a62a5 289184 libs optional libcurl3-gnutls_7.52.1-5+deb9u2_amd64.deb c2def1c0fb0920117ed2e1e972568813 294756 libs optional libcurl3-nss_7.52.1-5+deb9u2_amd64.deb ceff24abe48d25e7b712176ef75ea8dd 291002 libs optional libcurl3_7.52.1-5+deb9u2_amd64.deb 7bff04c46d4de18a1490669620869be9 827470 doc optional libcurl4-doc_7.52.1-5+deb9u2_all.deb cc8726dfd9a83e14c06e491cca66b0c5 371738 libdevel optional libcurl4-gnutls-dev_7.52.1-5+deb9u2_amd64.deb c40f9754f1a97af58635e2b30e3ac0d9 377610 libdevel optional libcurl4-nss-dev_7.52.1-5+deb9u2_amd64.deb 31f292c80132ffbe42c700228ccc9d67 373660 libdevel optional libcurl4-openssl-dev_7.52.1-5+deb9u2_amd64.deb -----BEGIN PGP SIGNATURE----- iQJFBAEBCgAvFiEEBsId305pBx+F583DbwzL4CFiRygFAlntBZMRHGdoZWRvQGRl Ymlhbi5vcmcACgkQbwzL4CFiRyh0bA//fmsz4J5HYNkUjD3BDQGj2xTdq5iy50mm YfzAO6BrZaTpVc+ytggeX82AhKiD+8SXeEujcnMBhYinVHgPcVhV0cgnE3HM/opv bxTF/viwPAogz1npRUx79gY7idXvtUDMYvdg5lcc4za1Kvv1pbq6RZDxJY5XeiZs zLG8QFmS0w82EtSfSYT4U9PlG8prRq5NEOcfzFXN7+46pJ1zngLc83RVXSo9TYrA IhCMjP3HueN+9xMAF0xntYzjezGK2F76ZKmHml+M1oKfzvVTP+ZhWCFhMd46vOdI eDsnL+NaGToa3ur/Ufw4xKEmd8neUkvsUvOm9pBWwDQq77Gs7MAMI9/zeoGhSOY4 wWspk7GDDtmPj36UzL1+iEn3G4ODwZYZ0JJVXG9gP3Ezn8+VNQqyCo1S1A8lgk5J 3sSrd6yH2aOGOxOJsGoIeENPCSl1y5zEEKS0GoPtzZljDLW7+VXK+o+xkdAXrZzF ts4rrWYOuR37TqNpfZ+RfOKXWVcWvuAYrQtFknUi8fml/COnPS+RjfjhLHUQ3uFO 0jULfbSGRpw2VHkNi62qkA2yVenbElj2s2KSavHsXUlDQUxpW+G4R9G/V8C+0EUc GZFr/bS2dDKNZtv/87GUW1KBpVpHJhf/R1YHmCJAfVhvInuXmAhTxeO6Uqh9xHNl lm/q2RjJP3w= =fiZR -----END PGP SIGNATURE-----