-----BEGIN PGP SIGNED MESSAGE----- Hash: SHA512 Format: 1.8 Date: Tue, 15 May 2018 23:00:28 +0100 Source: curl Binary: curl libcurl3 libcurl3-gnutls libcurl3-nss libcurl4-openssl-dev libcurl4-gnutls-dev libcurl4-nss-dev libcurl3-dbg libcurl4-doc Architecture: source amd64 all Version: 7.52.1-5+deb9u6 Distribution: stretch-security Urgency: high Maintainer: Alessandro Ghedini <ghedo@debian.org> Changed-By: Alessandro Ghedini <ghedo@debian.org> Description: curl - command line tool for transferring data with URL syntax libcurl3 - easy-to-use client-side URL transfer library (OpenSSL flavour) libcurl3-dbg - debugging symbols for libcurl (OpenSSL, GnuTLS and NSS flavours) libcurl3-gnutls - easy-to-use client-side URL transfer library (GnuTLS flavour) libcurl3-nss - easy-to-use client-side URL transfer library (NSS flavour) libcurl4-doc - documentation for libcurl libcurl4-gnutls-dev - development files and documentation for libcurl (GnuTLS flavour) libcurl4-nss-dev - development files and documentation for libcurl (NSS flavour) libcurl4-openssl-dev - development files and documentation for libcurl (OpenSSL flavour) Changes: curl (7.52.1-5+deb9u6) stretch-security; urgency=high . * Fix heap buffer over-read when parsing bad RTSP headers as per CVE-2018-1000301 https://curl.haxx.se/docs/adv_2018-b138.html Checksums-Sha1: 38fb26ec8203e15db32ee5dae81aa0226513fe93 2793 curl_7.52.1-5+deb9u6.dsc 1a63f0791e3cbb7586973b952c88357d8c8e0b25 40420 curl_7.52.1-5+deb9u6.debian.tar.xz 2ab750d44ac3456d5a60b39085de31b492b477c6 131982 curl-dbgsym_7.52.1-5+deb9u6_amd64.deb 80d993068eb41a5b805a8d3668d0d1a17a197bed 11020 curl_7.52.1-5+deb9u6_amd64.buildinfo f018385fdb8933a289570115a51d99272b42b769 227506 curl_7.52.1-5+deb9u6_amd64.deb dcfe2e1d47ef20badb49df2a0540cb774f2d3a16 5001348 libcurl3-dbg_7.52.1-5+deb9u6_amd64.deb e869a9f70bb145a77a08a97bf19a855dbe6b4526 289582 libcurl3-gnutls_7.52.1-5+deb9u6_amd64.deb 5f5d72e672e134ed221f42d40dab37324e1ffc5d 295364 libcurl3-nss_7.52.1-5+deb9u6_amd64.deb 09e1a3daddd3ce3eda31c057085869fd3d81968f 291338 libcurl3_7.52.1-5+deb9u6_amd64.deb 9426c24880fcc19d334a5ce2974d3e1ad01a3626 827774 libcurl4-doc_7.52.1-5+deb9u6_all.deb 8ca7ee5944e40f75e58b35d72979282dd813df76 372388 libcurl4-gnutls-dev_7.52.1-5+deb9u6_amd64.deb 950497fd5ec36bce3aacc1db809b149de09d57ee 377738 libcurl4-nss-dev_7.52.1-5+deb9u6_amd64.deb 2da5160e04003f3708ced1bacd08779b1ccbeeca 374060 libcurl4-openssl-dev_7.52.1-5+deb9u6_amd64.deb Checksums-Sha256: 463a6ac7cb310890ae03c904ec31f85616cf05bd56c74d1d9b981da38bfab616 2793 curl_7.52.1-5+deb9u6.dsc df3786154af6f98fa3623272a1756355218fd686603259b441b3a4ae24d7a942 40420 curl_7.52.1-5+deb9u6.debian.tar.xz 79cc1e0b82763a9a59da95e2101ad266da78b52bd43ce5607a7d98eaddf9bf34 131982 curl-dbgsym_7.52.1-5+deb9u6_amd64.deb 7d42ff4eae66a2abc09bca73e9f0e59b32b2b8804be028c212dae22ca074a70f 11020 curl_7.52.1-5+deb9u6_amd64.buildinfo ffbe48b2248e6f666fb7af3c72b9d0a0febbb35c8b075177c9040eefe09354ec 227506 curl_7.52.1-5+deb9u6_amd64.deb 7f074fe26c26896d7bd1cdde0c16132b2c74bcf618cd72a5c6d7b486b741f1ed 5001348 libcurl3-dbg_7.52.1-5+deb9u6_amd64.deb 14bbd55f9854206ca1374484c5d9fc9b53d7d7283105d51d10f65e48e247604d 289582 libcurl3-gnutls_7.52.1-5+deb9u6_amd64.deb d38d62f17ff911ad879f10084eec886e1d2d83e864409baa3609c37291c7b0f9 295364 libcurl3-nss_7.52.1-5+deb9u6_amd64.deb cf6c7a59223ac7cca153212c058f753c6a1458507dbdaa97c230ea99492ef301 291338 libcurl3_7.52.1-5+deb9u6_amd64.deb 49ed7bd52027cb97e3f9f173b265d9bc9f37196fa0f0bb4053b8e940a3953777 827774 libcurl4-doc_7.52.1-5+deb9u6_all.deb 781e316438f78f84e08eb3163026b009cec6110830cd2eb4eb4c1c0d332f850c 372388 libcurl4-gnutls-dev_7.52.1-5+deb9u6_amd64.deb 1f3dae839729fd881400092e71520a718f9867380b64762bd6a29d089c4e17cf 377738 libcurl4-nss-dev_7.52.1-5+deb9u6_amd64.deb ce495febc517a8bbcb9eb7442194fd83cfa9deb3255171a4b628de00f99a1820 374060 libcurl4-openssl-dev_7.52.1-5+deb9u6_amd64.deb Files: 4b7cc463aa9531ccb4981f645c8c463a 2793 web optional curl_7.52.1-5+deb9u6.dsc 6439d85c93abf5b67d2cbd983ae858ac 40420 web optional curl_7.52.1-5+deb9u6.debian.tar.xz 0f4561061f60243dddb0210c02b578a6 131982 debug extra curl-dbgsym_7.52.1-5+deb9u6_amd64.deb a0c48227afc3ac23bbfcf6cb6e00cea4 11020 web optional curl_7.52.1-5+deb9u6_amd64.buildinfo a357c7d551d0135474cdf1dbc7cc5d0b 227506 web optional curl_7.52.1-5+deb9u6_amd64.deb 3b5a223672507c4079f89cd30b85e2c2 5001348 debug extra libcurl3-dbg_7.52.1-5+deb9u6_amd64.deb 5c868d9015983d177527cd20a069504c 289582 libs optional libcurl3-gnutls_7.52.1-5+deb9u6_amd64.deb 95efdb2ceb21229d2782046be4f1cd45 295364 libs optional libcurl3-nss_7.52.1-5+deb9u6_amd64.deb f21bda2dfb5dd3bfc6a5e48b247f50cc 291338 libs optional libcurl3_7.52.1-5+deb9u6_amd64.deb e54d502fecdf66cacac99526aca03b4a 827774 doc optional libcurl4-doc_7.52.1-5+deb9u6_all.deb 551af55a46089a9b3e54dd93c26195e4 372388 libdevel optional libcurl4-gnutls-dev_7.52.1-5+deb9u6_amd64.deb 5c4031ec11a48003eee552e9e87bd856 377738 libdevel optional libcurl4-nss-dev_7.52.1-5+deb9u6_amd64.deb 03c8d2d01eac2a632981e20046837dce 374060 libdevel optional libcurl4-openssl-dev_7.52.1-5+deb9u6_amd64.deb -----BEGIN PGP SIGNATURE----- iQIzBAEBCgAdFiEEBsId305pBx+F583DbwzL4CFiRygFAlr7bF8ACgkQbwzL4CFi RyijGg/6Aj5IQac9uKI87z7ArXjGFJDLk+xvvJuUMrd2PafGA1K+adwp880ELM8c a/K3OrXlB8LgjNlRcI1/dQ/JLTlAtgzdlHZIQL5AgmseJwijZs8LpFLql7iC432Z IC7Re7+dlP+s15tf85NhqJwrcT7I9XjVZ+077fnCYGxH5JZ3eEAcin+Rsj2wEPLC 2oDLcKs0uZggk8cX9AxnGiK2hTzthJk1WP15KBkh2UN+k0y0UMOUyOjnEXY2Tzwp rHOR4cYesyJbq6EFEnetr5uX1lpqAhj5ZbxVFdWs6f9D17f5qSMDWM/75RU9Z59E LoM2DGRfNUaHZE/s8C4iaJOnqaQeglDaPA28hpdait0fGGjhyMNJUaH3LfrpXh9P PWT2oOPzXyRjLWzXycItZAVDxm6mTNo1O23yYhsmNQwBdmwEjhHvrUeI18t+tYQL U0iPxXXGZwlkBFI9qd6sno1hHhiFogHiwSXzqYJzO39vZEwlRj2WPZM5R9cJEV68 RGgJ4VWkjSrh1jzWZoVF/4M1GgeWQ2rNayzv1sLOzYaEmqD/iq/eeBmzW+OcwlGs nFBfZybpg2P/12aNS3gtnFbUQ4QMxnapPYkS8ikqvMBXDHzhcVhaApxoHz9xhLNo qewzC/wZjclK1CzEFsnxs38rCIxLn2+qakO7Pv1P51mKIxWHdus= =e0jx -----END PGP SIGNATURE-----