-----BEGIN PGP SIGNED MESSAGE----- Hash: SHA512 Format: 1.8 Date: Mon, 03 Sep 2018 23:50:29 +0100 Source: curl Binary: curl libcurl3 libcurl3-gnutls libcurl3-nss libcurl4-openssl-dev libcurl4-gnutls-dev libcurl4-nss-dev libcurl3-dbg libcurl4-doc Architecture: source Version: 7.52.1-5+deb9u7 Distribution: stretch-security Urgency: high Maintainer: Alessandro Ghedini <ghedo@debian.org> Changed-By: Alessandro Ghedini <ghedo@debian.org> Description: curl - command line tool for transferring data with URL syntax libcurl3 - easy-to-use client-side URL transfer library (OpenSSL flavour) libcurl3-dbg - debugging symbols for libcurl (OpenSSL, GnuTLS and NSS flavours) libcurl3-gnutls - easy-to-use client-side URL transfer library (GnuTLS flavour) libcurl3-nss - easy-to-use client-side URL transfer library (NSS flavour) libcurl4-doc - documentation for libcurl libcurl4-gnutls-dev - development files and documentation for libcurl (GnuTLS flavour) libcurl4-nss-dev - development files and documentation for libcurl (NSS flavour) libcurl4-openssl-dev - development files and documentation for libcurl (OpenSSL flavour) Changes: curl (7.52.1-5+deb9u7) stretch-security; urgency=high . * Fix NTLM password overflow via integer overflow as per CVE-2018-14618 https://curl.haxx.se/docs/CVE-2018-14618.html Checksums-Sha1: 9e6d09b8d728ee14fe77a171502dff11ed0968ed 2818 curl_7.52.1-5+deb9u7.dsc 48070b88de9e093c4e192310f12b55305f226bd3 40796 curl_7.52.1-5+deb9u7.debian.tar.xz 2b5eb0896cad2480a662c3a1d77f01aae5ea012c 11128 curl_7.52.1-5+deb9u7_amd64.buildinfo Checksums-Sha256: e8f007d8d45d4d00ba5aa54223f46b8c240a72fb2c4e45d80a859124e3ef40d0 2818 curl_7.52.1-5+deb9u7.dsc dbe0d4258f0d91787be2197f175807a69a454c9463e7dec3539f168cc43d1b40 40796 curl_7.52.1-5+deb9u7.debian.tar.xz 517c6d49e03cfad49ca20ad4945472a3799e3c76bc8f557a0775645312de6ec3 11128 curl_7.52.1-5+deb9u7_amd64.buildinfo Files: b7aab8bd6883c46e0337b41e2e9274d1 2818 web optional curl_7.52.1-5+deb9u7.dsc 7c6282a12176e36e99e3dc2a00481a72 40796 web optional curl_7.52.1-5+deb9u7.debian.tar.xz 5ee7189e2cbf987ac0640fa87531a197 11128 web optional curl_7.52.1-5+deb9u7_amd64.buildinfo -----BEGIN PGP SIGNATURE----- iQJFBAEBCgAvFiEEBsId305pBx+F583DbwzL4CFiRygFAluNwIERHGdoZWRvQGRl Ymlhbi5vcmcACgkQbwzL4CFiRyjHQw/7B7bPpjGyTXzLSV/CfLfydT9FRGQNSxvy GIy4DqGduqhMcCEZndhL80pw+604cTIX+d+3BgWB/iPx71pAo7nJYvrz8eCp9GeS 0po/XHRgUPymCHIeDvhPbChheeXcI+2kxkoU91A8fkKpyJEif+kAQLC+cvCuz9Hz o2kCn4wGM1WvHZyWWBWJ7uHcEJxvL37WtO0b6BAM77SECjz2CY4LiIWsGHWvWsl6 nWbYKrCUIZJAPi2KlO0KZdn9Tpx/pJXFfaHJXKNxhYCfA6qK8FMKLWespB7Jsfy7 hl2a2DZcQFohJGPNAqnKFfPXkurV9cgJxozw2GXPsruQtvLJKd+c8Eb6/NYjjbcD xHLeEXFweLkOkZIAcypOAsL1kR+BruK57EULBWBYzu9e767kagVdzMQZu7eGgpI6 VZqv0YIDcHfChLuMpL8B8SqDXjWs78yBHalD0i2HUoZWB+a8DM4t8DVHrw7+fFl2 blgeW9sYOtLhxyVfEz6P03USNezxVeyKh+Fvk7OkNZF3l4WLEgdkbO74uafJb9+R tp05zCvi8SsMJ2ED00XkCiutXXoBdDcpNtK/8iY71F6eHCxjZhWZek/sN1CoWUj0 PPCaizseV++mSLDgoYCTn8j5OKxmhhocTHegEl6dmIQS+K6JT6mxJl8TASyDyVdw UB9lEIq1/Ls= =YCCL -----END PGP SIGNATURE-----