curl 7.42.1-3ubuntu1 source package in Ubuntu

Changelog

curl (7.42.1-3ubuntu1) wily; urgency=low

  * Merge from Debian (LP: #1459685). Remaining changes:
    - Drop dependencies not in main:
      + Build-Depends: Drop stunnel4 and libssh2-1-dev.
      + Drop libssh2-1-dev from binary package Depends.
  * Dropped patches:
    - debian/patches/CVE-2015-3143.patch: upstream
    - debian/patches/CVE-2015-3148.patch: upstream
    - debian/patches/CVE-2015-3144.patch: upstream
    - debian/patches/CVE-2015-3153.patch: upstream
    - debian/patches/CVE-2014-8150.patch: upstream
    - debian/patches/CVE-2015-3145.patch: upstream
  * Dropped changes:
    - Add new libcurl3-udeb package.
    - Add new curl-udeb package.
      they seems to be broken since pre-trusty

curl (7.42.1-3) unstable; urgency=medium

  * Update copyright
  * Set both CA bundle and CA path default values for OpenSSL and GnuTLS
    backends
  * Bump versioned depends on libgnutls to workaround lack of nettle versioned
    symbols (Closes: #787960)

curl (7.42.1-2) unstable; urgency=medium

  * Switch curl binary to libcurl3-gnutls (Closes: #342719)
    This is the first step of a possible migration to a GnuTLS-only
    libcurl for Debian. Let's see how it goes.

curl (7.42.1-1) unstable; urgency=high

  * New upstream release
    - Don't send sensitive HTTP server headers to proxies as per
      CVE-2015-3153
      http://curl.haxx.se/docs/adv_20150429.html
  * Drop 08_fix-spelling.patch (merged upstream)
  * Refresh patches

curl (7.42.0-1) unstable; urgency=medium

  * New upstream release
    - Fix re-using authenticated connection when unauthenticated
      as per CVE-2015-3143
      http://curl.haxx.se/docs/adv_20150422A.html
    - Fix host name out of boundary memory access as per CVE-2015-3144
      http://curl.haxx.se/docs/adv_20150422D.html
    - Fix cookie parser out of boundary memory access as per CVE-2015-3145
      http://curl.haxx.se/docs/adv_20150422C.html
    - Fix Negotiate not treated as connection-oriented as per CVE-2015-3148
      http://curl.haxx.se/docs/adv_20150422B.html
    - Disable SSLv3 in the OpenSSL backend when OPENSSL_NO_SSL3_METHOD is
      defined (Closes: #768562)
  * Drop patches merged upstream
  * Refresh patches
  * Bump Standards-Version to 3.9.6 (no changes needed)

curl (7.38.0-4) unstable; urgency=high

  * Fix URL request injection vulnerability as per CVE-2014-8150
    http://curl.haxx.se/docs/adv_20150108B.html
  * Set urgency=high accordingly

 -- Gianfranco Costamagna <email address hidden>  Mon, 08 Jun 2015 10:35:57 +0200

Upload details

Uploaded by:
Gianfranco Costamagna
Sponsored by:
Adam Conrad
Uploaded to:
Wily
Original maintainer:
Ubuntu Developers
Architectures:
any all
Section:
web
Urgency:
Very Urgent

See full publishing history Publishing

Series Pocket Published Component Section

Downloads

File Size SHA-256 Checksum
curl_7.42.1.orig.tar.gz 4.1 MiB 4fc504f4fac56d091162707941d06c72a4222fc6fa48ca8193e44ee74baf079c
curl_7.42.1-3ubuntu1.debian.tar.xz 27.3 KiB b4ba5cab70b56d00b95d5723ece7d484dd4bd8a1a09e8e36168893ead02c53ce
curl_7.42.1-3ubuntu1.dsc 2.6 KiB 53e18b4200016211ddfc430020f236ae6bb64af499957da3aced6d9c1ee1655b

View changes file

Binary packages built by this source

curl: No summary available for curl in ubuntu wily.

No description available for curl in ubuntu wily.

curl-dbgsym: No summary available for curl-dbgsym in ubuntu wily.

No description available for curl-dbgsym in ubuntu wily.

libcurl3: No summary available for libcurl3 in ubuntu wily.

No description available for libcurl3 in ubuntu wily.

libcurl3-dbg: No summary available for libcurl3-dbg in ubuntu wily.

No description available for libcurl3-dbg in ubuntu wily.

libcurl3-dbgsym: No summary available for libcurl3-dbgsym in ubuntu wily.

No description available for libcurl3-dbgsym in ubuntu wily.

libcurl3-gnutls: No summary available for libcurl3-gnutls in ubuntu wily.

No description available for libcurl3-gnutls in ubuntu wily.

libcurl3-gnutls-dbgsym: No summary available for libcurl3-gnutls-dbgsym in ubuntu wily.

No description available for libcurl3-gnutls-dbgsym in ubuntu wily.

libcurl3-nss: No summary available for libcurl3-nss in ubuntu wily.

No description available for libcurl3-nss in ubuntu wily.

libcurl3-nss-dbgsym: No summary available for libcurl3-nss-dbgsym in ubuntu wily.

No description available for libcurl3-nss-dbgsym in ubuntu wily.

libcurl4-doc: No summary available for libcurl4-doc in ubuntu wily.

No description available for libcurl4-doc in ubuntu wily.

libcurl4-gnutls-dev: No summary available for libcurl4-gnutls-dev in ubuntu wily.

No description available for libcurl4-gnutls-dev in ubuntu wily.

libcurl4-gnutls-dev-dbgsym: No summary available for libcurl4-gnutls-dev-dbgsym in ubuntu wily.

No description available for libcurl4-gnutls-dev-dbgsym in ubuntu wily.

libcurl4-nss-dev: No summary available for libcurl4-nss-dev in ubuntu wily.

No description available for libcurl4-nss-dev in ubuntu wily.

libcurl4-nss-dev-dbgsym: No summary available for libcurl4-nss-dev-dbgsym in ubuntu wily.

No description available for libcurl4-nss-dev-dbgsym in ubuntu wily.

libcurl4-openssl-dev: No summary available for libcurl4-openssl-dev in ubuntu wily.

No description available for libcurl4-openssl-dev in ubuntu wily.

libcurl4-openssl-dev-dbgsym: No summary available for libcurl4-openssl-dev-dbgsym in ubuntu wily.

No description available for libcurl4-openssl-dev-dbgsym in ubuntu wily.