Format: 1.8 Date: Wed, 04 Jan 2023 09:49:54 -0500 Source: curl Binary: curl libcurl3-gnutls libcurl3-nss libcurl4 libcurl4-doc libcurl4-gnutls-dev libcurl4-nss-dev libcurl4-openssl-dev Built-For-Profiles: noudeb Architecture: amd64 all Version: 7.85.0-1ubuntu0.2 Distribution: kinetic Urgency: medium Maintainer: Launchpad Build Daemon Changed-By: Marc Deslauriers Description: curl - command line tool for transferring data with URL syntax libcurl3-gnutls - easy-to-use client-side URL transfer library (GnuTLS flavour) libcurl3-nss - easy-to-use client-side URL transfer library (NSS flavour) libcurl4 - easy-to-use client-side URL transfer library (OpenSSL flavour) libcurl4-doc - documentation for libcurl libcurl4-gnutls-dev - development files and documentation for libcurl (GnuTLS flavour) libcurl4-nss-dev - development files and documentation for libcurl (NSS flavour) libcurl4-openssl-dev - development files and documentation for libcurl (OpenSSL flavour) Changes: curl (7.85.0-1ubuntu0.2) kinetic-security; urgency=medium . * SECURITY UPDATE: Another HSTS bypass via IDN - debian/patches/CVE-2022-43551.patch: use the IDN decoded name in HSTS checks in lib/http.c. - CVE-2022-43551 * SECURITY UPDATE: HTTP Proxy deny use-after-free - debian/patches/CVE-2022-43552.patch: do not free the protocol struct in *_done() in lib/smb.c, lib/telnet.c. - CVE-2022-43552 Checksums-Sha1: 3221635944816dfa553495cfaee74a88c29809d7 162156 curl-dbgsym_7.85.0-1ubuntu0.2_amd64.ddeb 33468fd06057765d9c2aadead8e58b848b5c6d93 13050 curl_7.85.0-1ubuntu0.2_amd64.buildinfo ab5801375de2988d97dc41fc6504d18dec91e490 199192 curl_7.85.0-1ubuntu0.2_amd64.deb 64d6d346eee1495bc3603658185d5e57a640eeaa 1014848 libcurl3-gnutls-dbgsym_7.85.0-1ubuntu0.2_amd64.ddeb c41ce5619a59ebd0f1ca35a69ccc920f252a5f44 288278 libcurl3-gnutls_7.85.0-1ubuntu0.2_amd64.deb c8070474ba72ed9060e21d21eeb498ee02001e6f 1061070 libcurl3-nss-dbgsym_7.85.0-1ubuntu0.2_amd64.ddeb b2a67c3bae0c190e0ef20aee5200be17beb6e2ce 295688 libcurl3-nss_7.85.0-1ubuntu0.2_amd64.deb 52ff8b4b95daf460d78be1629d1445458c13734a 1041592 libcurl4-dbgsym_7.85.0-1ubuntu0.2_amd64.ddeb 82e3290205ff6963288dfa3cd4e89df9ea7c3489 966880 libcurl4-doc_7.85.0-1ubuntu0.2_all.deb b3a96855902ae9b14d59eceb9be0654cfd347472 386214 libcurl4-gnutls-dev_7.85.0-1ubuntu0.2_amd64.deb 95850ef9ef731795ac453a5d370109882e1c9e7b 395690 libcurl4-nss-dev_7.85.0-1ubuntu0.2_amd64.deb bc4737261cdf9446849383e4bc2c3bc5b5cb5a3c 392476 libcurl4-openssl-dev_7.85.0-1ubuntu0.2_amd64.deb 68be45a23e53f64e7df3e605aee0ca70008b8756 293230 libcurl4_7.85.0-1ubuntu0.2_amd64.deb Checksums-Sha256: b91c9c6a2e2601c0edb12065ab03705957f9419146b240ad8d60889424d0d5f5 162156 curl-dbgsym_7.85.0-1ubuntu0.2_amd64.ddeb 1c41cc2a61761d0ef933d98149e559f03cfd11943ee61796eac74989206b7f6f 13050 curl_7.85.0-1ubuntu0.2_amd64.buildinfo d1c28ecbc956f526cbba7c3e8ac492a7d12a3898674d18f6619d9bf1c1433cdf 199192 curl_7.85.0-1ubuntu0.2_amd64.deb 340a014c41aca3f78db2d90f7185db1fdb175f099c11e75980d3b54df7eae689 1014848 libcurl3-gnutls-dbgsym_7.85.0-1ubuntu0.2_amd64.ddeb 2e3dfab30796e0b4797a7dada768048825bcc3cffdea58bb5ab2aa4e273469fa 288278 libcurl3-gnutls_7.85.0-1ubuntu0.2_amd64.deb a0ef379963acff6d51f474d62d02ba8aa32f3777e3c59a82c1a92e1d70645b7e 1061070 libcurl3-nss-dbgsym_7.85.0-1ubuntu0.2_amd64.ddeb 931ff37e435dd849c7b207909e9e506eff1a3d3d470e2183ad444880afca8a2a 295688 libcurl3-nss_7.85.0-1ubuntu0.2_amd64.deb ca01125b5cb7122dcfd1dd98ec113bc6e64a630531b5e637b3b7c0f3b79884ae 1041592 libcurl4-dbgsym_7.85.0-1ubuntu0.2_amd64.ddeb bfd0f42fbe368481f99682c7b604b1180d107e6e4a2c7b8bc866c9ef2a5cec76 966880 libcurl4-doc_7.85.0-1ubuntu0.2_all.deb bf86bfaf133cf7741614e660b494fa2077ff5b30386c60dd822dbeac203075a5 386214 libcurl4-gnutls-dev_7.85.0-1ubuntu0.2_amd64.deb 343e2122438db5c62fec77e766a80e61e1943c3b8d2808698592af2e6c5c1cb6 395690 libcurl4-nss-dev_7.85.0-1ubuntu0.2_amd64.deb 3c5a67e0261ceca904a1037a15063a69df18a770da711687ec935cb31defaed2 392476 libcurl4-openssl-dev_7.85.0-1ubuntu0.2_amd64.deb cfa8d15c0733a61b4fcecacd08ed2260b36f6751a8a1cb634b22f96d8e2803d6 293230 libcurl4_7.85.0-1ubuntu0.2_amd64.deb Files: 1ea0f443bc9c23c2d24eac3855ff757a 162156 debug optional curl-dbgsym_7.85.0-1ubuntu0.2_amd64.ddeb ca5f821ac5604e5f73ebf817e080ec26 13050 web optional curl_7.85.0-1ubuntu0.2_amd64.buildinfo fde04957b805de8c0800a7e6f649d696 199192 web optional curl_7.85.0-1ubuntu0.2_amd64.deb 96cd260aec1ca61cbacea7f6886c09cd 1014848 debug optional libcurl3-gnutls-dbgsym_7.85.0-1ubuntu0.2_amd64.ddeb b609a88084e1b1fb74ff0ab6007de0c0 288278 libs optional libcurl3-gnutls_7.85.0-1ubuntu0.2_amd64.deb 79fa7b355844616f03d5bde3bf00d9b9 1061070 debug optional libcurl3-nss-dbgsym_7.85.0-1ubuntu0.2_amd64.ddeb b13117fd1cf3d43172231a1f0a43bc32 295688 libs optional libcurl3-nss_7.85.0-1ubuntu0.2_amd64.deb 05ffeb0eb01b18fb9b15441d2b63415a 1041592 debug optional libcurl4-dbgsym_7.85.0-1ubuntu0.2_amd64.ddeb 7a0b1706367076186a46471afd2f727f 966880 doc optional libcurl4-doc_7.85.0-1ubuntu0.2_all.deb 4c3a3625edd2d71693eafeb27777361e 386214 libdevel optional libcurl4-gnutls-dev_7.85.0-1ubuntu0.2_amd64.deb ad771c6d48534cd3defb602860a1092a 395690 libdevel optional libcurl4-nss-dev_7.85.0-1ubuntu0.2_amd64.deb 5ea55015982f904c1d4adda2dc99efc3 392476 libdevel optional libcurl4-openssl-dev_7.85.0-1ubuntu0.2_amd64.deb bb8b685f513a83bca311d643ce468a7a 293230 libs optional libcurl4_7.85.0-1ubuntu0.2_amd64.deb Original-Maintainer: Alessandro Ghedini