Format: 1.8 Date: Fri, 06 Sep 2019 15:00:31 +0930 Source: curl Binary: curl libcurl3 libcurl3-gnutls libcurl3-nss libcurl4-openssl-dev libcurl4-gnutls-dev libcurl4-nss-dev libcurl3-dbg libcurl4-doc Architecture: s390x Version: 7.47.0-1ubuntu2.14 Distribution: xenial Urgency: medium Maintainer: Launchpad Build Daemon Changed-By: Alex Murray Description: curl - command line tool for transferring data with URL syntax libcurl3 - easy-to-use client-side URL transfer library (OpenSSL flavour) libcurl3-dbg - debugging symbols for libcurl (OpenSSL, GnuTLS and NSS flavours) libcurl3-gnutls - easy-to-use client-side URL transfer library (GnuTLS flavour) libcurl3-nss - easy-to-use client-side URL transfer library (NSS flavour) libcurl4-doc - documentation for libcurl libcurl4-gnutls-dev - development files and documentation for libcurl (GnuTLS flavour) libcurl4-nss-dev - development files and documentation for libcurl (NSS flavour) libcurl4-openssl-dev - development files and documentation for libcurl (OpenSSL flavour) Changes: curl (7.47.0-1ubuntu2.14) xenial-security; urgency=medium . * SECURITY UPDATE: double-free when using kerberos over FTP may cause denial-of-service - debian/patches/CVE-2019-5481.patch: update lib/security.c to avoid double-free on large memory allocation failures - CVE-2019-5481 * SECURITY UPDATE: heap buffer overflow when receiving TFTP data may cause denial-of-service or remote code-execution - debian/patches/CVE-2019-5482.patch: ensure to use the correct block size when calling recvfrom() if the server returns an OACK without specifying a block size in lib/tftp.c - CVE-2019-5482 Checksums-Sha1: 634a9bde4e808165b15abe0a0b875b8a9df54321 1086 curl-dbgsym_7.47.0-1ubuntu2.14_s390x.ddeb 211fc07e40098c254bc8effcdc5f812fa2585dfc 136934 curl_7.47.0-1ubuntu2.14_s390x.deb 52dc1c0b7e602eb427a44fc6f94cf8d9a19c3c9a 3597374 libcurl3-dbg_7.47.0-1ubuntu2.14_s390x.deb 75177b8dc23d249076776e6ed39bcf92ce005a8b 1204 libcurl3-dbgsym_7.47.0-1ubuntu2.14_s390x.ddeb 9f3f088ab6d50237aa25a5ee2c73674ce85637c4 1212 libcurl3-gnutls-dbgsym_7.47.0-1ubuntu2.14_s390x.ddeb 070a9b7ad03054fb1ff10cc709c3b640bfdf50f7 173784 libcurl3-gnutls_7.47.0-1ubuntu2.14_s390x.deb 903d7c279e8003d0d5c3578f514f9d55a5f71cf4 1208 libcurl3-nss-dbgsym_7.47.0-1ubuntu2.14_s390x.ddeb 11a6875a85a40836398285e3fd89967542aeb57d 180610 libcurl3-nss_7.47.0-1ubuntu2.14_s390x.deb eb096d7efe67b6777453862d92c02f8350bc887b 175924 libcurl3_7.47.0-1ubuntu2.14_s390x.deb 79ee07fa11c6d1b5bacc7a225f9423907eef5e04 1292 libcurl4-gnutls-dev-dbgsym_7.47.0-1ubuntu2.14_s390x.ddeb 81405a5ccc75665f318726a99eefa5db741849a0 253262 libcurl4-gnutls-dev_7.47.0-1ubuntu2.14_s390x.deb 7cdb5405f8ed6ea13ed2610ebcb4f4e1d4d0b90e 1286 libcurl4-nss-dev-dbgsym_7.47.0-1ubuntu2.14_s390x.ddeb dcd681dbbecfbf0d8233e1f19c9264a45f440b98 260410 libcurl4-nss-dev_7.47.0-1ubuntu2.14_s390x.deb ff8e7c5e318504f02195d3930a2de882be84c138 1290 libcurl4-openssl-dev-dbgsym_7.47.0-1ubuntu2.14_s390x.ddeb 877dfbe4e6e03b011752c6064bacc5d78c70dfec 255004 libcurl4-openssl-dev_7.47.0-1ubuntu2.14_s390x.deb Checksums-Sha256: 7bb82c315aaa1c9be898968fbe702474c5078eb517b38bc0e0fb443ff428ba95 1086 curl-dbgsym_7.47.0-1ubuntu2.14_s390x.ddeb f21b2b737a60c42734faef0c2586f4cacce19a76c920b0b228615583ec7bf1e7 136934 curl_7.47.0-1ubuntu2.14_s390x.deb 34b424c8eda2c736e9cac2aba10686ca365f3065525a286bbb43aa7d85feb985 3597374 libcurl3-dbg_7.47.0-1ubuntu2.14_s390x.deb 9d11b548b8ce7203225ccbaf9621c3e9d2bdfd82e8921bd63aa4d4fa4e00ef24 1204 libcurl3-dbgsym_7.47.0-1ubuntu2.14_s390x.ddeb 5874141dc0e0b1d6a327621febcfc7de76b3181f3307299ef37aa2bcd10a5287 1212 libcurl3-gnutls-dbgsym_7.47.0-1ubuntu2.14_s390x.ddeb 6136af07c77a607cdc323c6b60be293a4e9aeebb2a599701bfc77d7b8bfadc4c 173784 libcurl3-gnutls_7.47.0-1ubuntu2.14_s390x.deb 63054ffb7122429ce3e8add9743da6eed4660f3a7bc78465dccb5aa60c227caa 1208 libcurl3-nss-dbgsym_7.47.0-1ubuntu2.14_s390x.ddeb 833b6a3c721855fed7c735dfee84a9dba01b2fff7f81e7affd0ccd258ecb4ca1 180610 libcurl3-nss_7.47.0-1ubuntu2.14_s390x.deb 4af1a7e3d771e19142518903b030d5e943c906955323372b3863e78caa2ac018 175924 libcurl3_7.47.0-1ubuntu2.14_s390x.deb 93e33772e473a4033f937e333fdc473d32e1b2cc73f23622e036e3b0336e1451 1292 libcurl4-gnutls-dev-dbgsym_7.47.0-1ubuntu2.14_s390x.ddeb 9f350bd6c7e132a4378acb26c4cb48617b8361107215b5a4ca0275df4dc3c992 253262 libcurl4-gnutls-dev_7.47.0-1ubuntu2.14_s390x.deb bbbea8f6c3a95d48ce406380fe2d542dfefa710ad795f23fa00b69cbf11224b0 1286 libcurl4-nss-dev-dbgsym_7.47.0-1ubuntu2.14_s390x.ddeb 34914f0e958debeb289fd874fa1e621fab8ecb9039712bd38d3d891f6a48102a 260410 libcurl4-nss-dev_7.47.0-1ubuntu2.14_s390x.deb ad8b1e920aa5c54dbe26b5865b0bb4d8d997005bcbbc132a11cd83a299174d99 1290 libcurl4-openssl-dev-dbgsym_7.47.0-1ubuntu2.14_s390x.ddeb ea4ca8655e3d343ab6b18a42b4ccf27d2c38e8fb150359073465fdbec1d8ea11 255004 libcurl4-openssl-dev_7.47.0-1ubuntu2.14_s390x.deb Files: 52e22edb0241c1a4cbb3067fab7e0a49 1086 web extra curl-dbgsym_7.47.0-1ubuntu2.14_s390x.ddeb 47cafbf9ab482d8393220880bfe93e94 136934 web optional curl_7.47.0-1ubuntu2.14_s390x.deb fae438dc2e58f785cad4cea55878bee1 3597374 debug extra libcurl3-dbg_7.47.0-1ubuntu2.14_s390x.deb 2d7035889acb5362469fe6d101798ed3 1204 libs extra libcurl3-dbgsym_7.47.0-1ubuntu2.14_s390x.ddeb c847c3ad81569729a76f5c77e1a30411 1212 libs extra libcurl3-gnutls-dbgsym_7.47.0-1ubuntu2.14_s390x.ddeb bdf056662e1db36a491f6f09330e118f 173784 libs optional libcurl3-gnutls_7.47.0-1ubuntu2.14_s390x.deb a713a0b941b423e78f8bd2b5f5887c1f 1208 libs extra libcurl3-nss-dbgsym_7.47.0-1ubuntu2.14_s390x.ddeb bb790ff0cd6a7da48d169d4f9fbf7e69 180610 libs optional libcurl3-nss_7.47.0-1ubuntu2.14_s390x.deb 72ab9b7c51dead86b1c1df421e084256 175924 libs optional libcurl3_7.47.0-1ubuntu2.14_s390x.deb cb68332a628d8919bdfe8a4c4d9f898f 1292 libdevel extra libcurl4-gnutls-dev-dbgsym_7.47.0-1ubuntu2.14_s390x.ddeb cb8e9f61a96b86604ec29edbed593b3a 253262 libdevel optional libcurl4-gnutls-dev_7.47.0-1ubuntu2.14_s390x.deb bb7c492d3de3d4a8afcecc0841b9d5a4 1286 libdevel extra libcurl4-nss-dev-dbgsym_7.47.0-1ubuntu2.14_s390x.ddeb a44ac583badcb8f520cae94ce15dc0cc 260410 libdevel optional libcurl4-nss-dev_7.47.0-1ubuntu2.14_s390x.deb 8cc5b9e9cf5de2ca0d53af0eb0700669 1290 libdevel extra libcurl4-openssl-dev-dbgsym_7.47.0-1ubuntu2.14_s390x.ddeb 4f9984e04684a299b18b15bd87df3c14 255004 libdevel optional libcurl4-openssl-dev_7.47.0-1ubuntu2.14_s390x.deb Original-Maintainer: Alessandro Ghedini