Format: 1.8 Date: Tue, 01 Apr 2014 09:25:23 -0400 Source: curl Binary: curl curl-udeb libcurl3 libcurl3-udeb libcurl3-gnutls libcurl3-nss libcurl4-openssl-dev libcurl4-gnutls-dev libcurl4-nss-dev libcurl3-dbg libcurl4-doc Architecture: i386 all Version: 7.35.0-1ubuntu2 Distribution: trusty-proposed Urgency: medium Maintainer: Ubuntu/amd64 Build Daemon Changed-By: Marc Deslauriers Description: curl - command line tool for transferring data with URL syntax curl-udeb - Get a file from an HTTP, HTTPS or FTP server (udeb) libcurl3 - easy-to-use client-side URL transfer library (OpenSSL flavour) libcurl3-dbg - debugging symbols for libcurl (OpenSSL, GnuTLS and NSS flavours) libcurl3-gnutls - easy-to-use client-side URL transfer library (GnuTLS flavour) libcurl3-nss - easy-to-use client-side URL transfer library (NSS flavour) libcurl3-udeb - Multi-protocol file transfer library (OpenSSL) (udeb) libcurl4-doc - documentation for libcurl libcurl4-gnutls-dev - development files and documentation for libcurl (GnuTLS flavour) libcurl4-nss-dev - development files and documentation for libcurl (NSS flavour) libcurl4-openssl-dev - development files and documentation for libcurl (OpenSSL flavour) Changes: curl (7.35.0-1ubuntu2) trusty; urgency=medium . * SECURITY UPDATE: wrong re-use of connections - debian/patches/CVE-2014-0138.patch: fix possible issues with NTLM HTTP logic, and extend new connection logic to other protocols in lib/http.c, lib/url.c, lib/urldata.h, add new tests to tests/data/Makefile.am, tests/data/test1418, tests/data/test1419. - CVE-2014-0138 * SECURITY UPDATE: incorrect wildcard SSL certificate validation with literal IP addresses - debian/patches/CVE-2014-0139.patch: fix wildcard logic in lib/hostcheck.c, added tests to tests/data/Makefile.am, tests/data/test1397, tests/unit/Makefile.inc, tests/unit/unit1397.c. - CVE-2014-0139 * debian/patches/fix_test172.path: fix expired cookie causing test to fail. Checksums-Sha1: 630159b7a5ce48671d443fd2d7cf656084956b2e 122606 curl_7.35.0-1ubuntu2_i386.deb 5253b6dcd5847d933b3ea4e3fc17805570127ab0 954 curl-udeb_7.35.0-1ubuntu2_i386.udeb bd5713ff2089e458fbef455f3ad882b52b261157 173944 libcurl3_7.35.0-1ubuntu2_i386.deb dd6db614f27ef952d5d440608847acecce7b63a1 838 libcurl3-udeb_7.35.0-1ubuntu2_i386.udeb a289d5fd35096d5ea008cb8a72a55dffd46d8300 166260 libcurl3-gnutls_7.35.0-1ubuntu2_i386.deb f270099354efb3f5e882e42922027199f6072920 176418 libcurl3-nss_7.35.0-1ubuntu2_i386.deb 43d48e3e04f0a85a9de94a6d6f56fb83e21ebdce 230134 libcurl4-openssl-dev_7.35.0-1ubuntu2_i386.deb 0e551894bf4c62b89d9a1100a879928e477f5a99 222912 libcurl4-gnutls-dev_7.35.0-1ubuntu2_i386.deb ce18e59b35737ec5a93d97773fb84af960e6635a 233860 libcurl4-nss-dev_7.35.0-1ubuntu2_i386.deb 9d6f8b02d132ea0a443adb30e65e819d5829c1a3 3100960 libcurl3-dbg_7.35.0-1ubuntu2_i386.deb 4dd6a4a2a78b95001faebf971ba0a8b97c9467c1 927522 libcurl4-doc_7.35.0-1ubuntu2_all.deb Checksums-Sha256: 11d902a8a15f6642bc0bc7342c4386c3d37a5b052f143ea181a4257e54b1a825 122606 curl_7.35.0-1ubuntu2_i386.deb 71a12096b94792fd9e6f3c76c2efa5ae8ffda873ba1cdde9018216f94a139611 954 curl-udeb_7.35.0-1ubuntu2_i386.udeb f67a26e6066facf6020ed82c4ee59e07552dfe4541d181b187c3ae04ae0e5bfa 173944 libcurl3_7.35.0-1ubuntu2_i386.deb b248c8903363ab4c3dd3cd9e7750469a1afdd81eee6f232d906e0bf86fd8cdd8 838 libcurl3-udeb_7.35.0-1ubuntu2_i386.udeb da575ff9bac390dfb971974ce982d1c83ccdeb5d04fd93562ce167901be8f349 166260 libcurl3-gnutls_7.35.0-1ubuntu2_i386.deb 4f95b6b0bd0e3037092ee7f88e73c653216b55a08cd098bf934aff67da1f693e 176418 libcurl3-nss_7.35.0-1ubuntu2_i386.deb f2ffde89c6f16d27eab02b04d503f1a3d9f3b471a96904af5aff7af6f487ac84 230134 libcurl4-openssl-dev_7.35.0-1ubuntu2_i386.deb 040360e06a869c093f66d07fc54ea3dedaa58a9b3984ead2c57df1af1d21d339 222912 libcurl4-gnutls-dev_7.35.0-1ubuntu2_i386.deb 0bb069fa4c10eaf9885452a16bc2d711b8943d352e9821a8817122be08e99f7c 233860 libcurl4-nss-dev_7.35.0-1ubuntu2_i386.deb 4d6d2ded1aa9aec1dfcb712476a78fb8240542ec5e6489232f482d6dc5d7dc3a 3100960 libcurl3-dbg_7.35.0-1ubuntu2_i386.deb 1da6543e45e091b473e0d05ab7bff3d60acf308ccad9215c8fa88a5a8053f717 927522 libcurl4-doc_7.35.0-1ubuntu2_all.deb Files: 0ba6ceb54a2a735a50b063bbe7da823b 122606 web optional curl_7.35.0-1ubuntu2_i386.deb 0a91cf13d60278f6c8f4b905595c6f06 954 debian-installer optional curl-udeb_7.35.0-1ubuntu2_i386.udeb d616fa3063c005b27efb17cdf0363075 173944 libs optional libcurl3_7.35.0-1ubuntu2_i386.deb 8a0f22c4bbf07051e9300361bbf8e35c 838 debian-installer optional libcurl3-udeb_7.35.0-1ubuntu2_i386.udeb aa594e7f3c63d4461f199523d47de80c 166260 libs optional libcurl3-gnutls_7.35.0-1ubuntu2_i386.deb 215a8e1a0f311fb14fa4485d2100a23d 176418 libs optional libcurl3-nss_7.35.0-1ubuntu2_i386.deb d03753fac067a662fb0aee34c505e1cb 230134 libdevel optional libcurl4-openssl-dev_7.35.0-1ubuntu2_i386.deb 382e6ba517acbce20fffc3722d961b43 222912 libdevel optional libcurl4-gnutls-dev_7.35.0-1ubuntu2_i386.deb ab3140fb6bf38541b1c32ee4349fa918 233860 libdevel optional libcurl4-nss-dev_7.35.0-1ubuntu2_i386.deb df93ac59163f1003848ddac1d91081de 3100960 debug extra libcurl3-dbg_7.35.0-1ubuntu2_i386.deb 1599c1a82c5a632c0427c38c56a3a919 927522 doc optional libcurl4-doc_7.35.0-1ubuntu2_all.deb Original-Maintainer: Alessandro Ghedini Package-Type: udeb