-----BEGIN PGP SIGNED MESSAGE----- Hash: SHA512 Format: 1.8 Date: Sun, 22 Oct 2017 22:01:06 +0100 Source: curl Binary: curl libcurl3 libcurl3-gnutls libcurl3-nss libcurl4-openssl-dev libcurl4-gnutls-dev libcurl4-nss-dev libcurl3-dbg libcurl4-doc Architecture: source amd64 all Version: 7.38.0-4+deb8u7 Distribution: jessie-security Urgency: medium Maintainer: Alessandro Ghedini <ghedo@debian.org> Changed-By: Alessandro Ghedini <ghedo@debian.org> Description: curl - command line tool for transferring data with URL syntax libcurl3 - easy-to-use client-side URL transfer library (OpenSSL flavour) libcurl3-dbg - debugging symbols for libcurl (OpenSSL, GnuTLS and NSS flavours) libcurl3-gnutls - easy-to-use client-side URL transfer library (GnuTLS flavour) libcurl3-nss - easy-to-use client-side URL transfer library (NSS flavour) libcurl4-doc - documentation for libcurl libcurl4-gnutls-dev - development files and documentation for libcurl (GnuTLS flavour) libcurl4-nss-dev - development files and documentation for libcurl (NSS flavour) libcurl4-openssl-dev - development files and documentation for libcurl (OpenSSL flavour) Changes: curl (7.38.0-4+deb8u7) jessie-security; urgency=medium . * Fix IMAP FETCH response out of bounds read as per CVE-2017-1000257 https://curl.haxx.se/docs/adv_20171023.html Checksums-Sha1: e70071067b17cf5be1dc067157ebb9e922619373 2694 curl_7.38.0-4+deb8u7.dsc 660ec4b6ce8bf78215d1f30dc7f635c950fc346b 42300 curl_7.38.0-4+deb8u7.debian.tar.xz f09008532f9cc505ce10361a7e696f7f49947ac8 200812 curl_7.38.0-4+deb8u7_amd64.deb 5c54deae98bc3ba970f3d31577511fcf2cd0f068 259316 libcurl3_7.38.0-4+deb8u7_amd64.deb 7f20e8a8691a18b354f91db907c1cbd9c25dd95b 251994 libcurl3-gnutls_7.38.0-4+deb8u7_amd64.deb 05fd785780223a7a5e893f1e3c55b66729319179 263156 libcurl3-nss_7.38.0-4+deb8u7_amd64.deb 986c42134bc8325cea9d759bc9886eec68b470de 337288 libcurl4-openssl-dev_7.38.0-4+deb8u7_amd64.deb 47cda6b5887b5be2063f1f20099f8b1c44bfb68b 328352 libcurl4-gnutls-dev_7.38.0-4+deb8u7_amd64.deb 28d8eb2013f061fc6535a4f27ad424df22403588 340868 libcurl4-nss-dev_7.38.0-4+deb8u7_amd64.deb 57e642ece17c098d140de6d0258d171e6fddbd49 3369494 libcurl3-dbg_7.38.0-4+deb8u7_amd64.deb fe72caebc720743d19269626248d42fc0f6cc30a 1066492 libcurl4-doc_7.38.0-4+deb8u7_all.deb Checksums-Sha256: b5bca99d184cfd436d441457df6c5eb660071dab4ff913fc5680278f39c80aa5 2694 curl_7.38.0-4+deb8u7.dsc 62f8e051409ecbe312a88ba9d4982784742d472d176eec16b4dd19859ae1398d 42300 curl_7.38.0-4+deb8u7.debian.tar.xz 57a15d42231b129cfec46f128f98c88ebc35c79d61960589bfdb680f825470d5 200812 curl_7.38.0-4+deb8u7_amd64.deb aed51deceb7c5e8603c177e49966a4b9212861cffd9924652a253f8b95e1c7fb 259316 libcurl3_7.38.0-4+deb8u7_amd64.deb 4bae3e9991a28908b8947079ce3deb2f691f81fa1ce6fc1cced68ca13b6d2cc4 251994 libcurl3-gnutls_7.38.0-4+deb8u7_amd64.deb da3ee9af64b5ab61959e00f98428b9bcb437502152f427670be49a565a78f1c7 263156 libcurl3-nss_7.38.0-4+deb8u7_amd64.deb 11fac404af4b69725e127dc9db653220b207ad7ca782bb7f146664bbac5d35f8 337288 libcurl4-openssl-dev_7.38.0-4+deb8u7_amd64.deb 9d286964ac3bc614dd7587f7844dc515abd9ae7c92795be69af4451543b569c6 328352 libcurl4-gnutls-dev_7.38.0-4+deb8u7_amd64.deb d2d44688f4b606be36082749dd161fa7a818cfb4e9c0f538b9bce0d33cbe6c82 340868 libcurl4-nss-dev_7.38.0-4+deb8u7_amd64.deb c8c088a997817fa8a28ad5419216ddca12f267f867cfdbf18e49593e9b9d473c 3369494 libcurl3-dbg_7.38.0-4+deb8u7_amd64.deb 6a75c6ae7c5d564947996904f9a5f04a767e58118336818f3725d3f8940ff241 1066492 libcurl4-doc_7.38.0-4+deb8u7_all.deb Files: f75e8523826ebec2b0ba01771829b18b 2694 web optional curl_7.38.0-4+deb8u7.dsc 9bb0d9a8c242c0244fbe90306cc2676a 42300 web optional curl_7.38.0-4+deb8u7.debian.tar.xz 461e93e53f04eedf9fba65695d195edd 200812 web optional curl_7.38.0-4+deb8u7_amd64.deb d2e807dc4318146affbe30deafe9109d 259316 libs optional libcurl3_7.38.0-4+deb8u7_amd64.deb 63bd6a9097d2a7b00615b5c6b56ca6fa 251994 libs optional libcurl3-gnutls_7.38.0-4+deb8u7_amd64.deb 11b6c5e43e0a98134896fcaab19b16d8 263156 libs optional libcurl3-nss_7.38.0-4+deb8u7_amd64.deb 31d15a1a5d4eee8a3422b51024ad7766 337288 libdevel optional libcurl4-openssl-dev_7.38.0-4+deb8u7_amd64.deb 39fbc382c4105c2e3c914eb886a2cb1d 328352 libdevel optional libcurl4-gnutls-dev_7.38.0-4+deb8u7_amd64.deb 9dd01137bee89cd26c6f62feb71b7a3e 340868 libdevel optional libcurl4-nss-dev_7.38.0-4+deb8u7_amd64.deb cd28cd7626781199c5481b69dc6e35a2 3369494 debug extra libcurl3-dbg_7.38.0-4+deb8u7_amd64.deb 03ee0ab794d1ab1a7081aa792e0867e6 1066492 doc optional libcurl4-doc_7.38.0-4+deb8u7_all.deb -----BEGIN PGP SIGNATURE----- iQJFBAEBCgAvFiEEBsId305pBx+F583DbwzL4CFiRygFAlntDZQRHGdoZWRvQGRl Ymlhbi5vcmcACgkQbwzL4CFiRyi5mA//VRk/6i6NOVAFYBrUh6ZIwErNQFahlsMe zss931h72uetZ0MJwpqBKy2BBmIMQNHlEm1YVM4frGxjzTTLPkHLi8b35cjUaFgY UU35ugMqiHxMVK+9TGLnWhYoXY2JAHIw5/QF6U8GjE6iPRMwMAFxP/9rwzMPwJyv WfPc3vQDN8mwCcNBPl1+r9EbTUMo/lE+j/m+9p5I7GkjfwCKLInmYF6R+Gt+MPFa XYjVsKRZgZ5jQvwF2mwUrxbrfdWO1YFelAV7lvNKoC62ZYo+VDR2Qc0TM48nh5ER VvZrl7qljWMBI/qgfdYvDXKsYVLSxg382ac5PWwQKIUM1MdxDo5hrW4xXKWxfwmw PJ0FQJltLFKNcOOn4IWY0xP3vqoDfA+/bVoI6gNPZyviiv/eGv+dsXKvO71UWY5h Rly3vG5KhcIvL/AqdZB52F+c/pMbABDKni25egDxZWm52qHb8f9JPitnhQLOHI2h yoehEN6+d1ifO1iPoAD2uNZ1uds8C/p1CMbR3+gVyINqP+TbgwrKVMpgxHhL3/rf zmAEVwcj5IHPjiZw4QT/QiSXnkOPkgopqlA1CZiLFh1raIFS4xAH5QJd3bOHbRG8 MpEVcoq6X2n1L5xP4YjMfDyAnKeB/5njZ4DUO0dSn+fu7Ex6zZaxJjsqxSQY8JoY dN8JLlltHsw= =3G5h -----END PGP SIGNATURE-----