Format: 1.8 Date: Mon, 20 Jun 2022 15:08:01 -0300 Source: curl Binary: curl libcurl3-gnutls libcurl3-nss libcurl4 libcurl4-gnutls-dev libcurl4-nss-dev libcurl4-openssl-dev Built-For-Profiles: noudeb Architecture: arm64 Version: 7.81.0-1ubuntu1.3 Distribution: jammy Urgency: medium Maintainer: Launchpad Build Daemon Changed-By: Leonidas Da Silva Barbosa Description: curl - command line tool for transferring data with URL syntax libcurl3-gnutls - easy-to-use client-side URL transfer library (GnuTLS flavour) libcurl3-nss - easy-to-use client-side URL transfer library (NSS flavour) libcurl4 - easy-to-use client-side URL transfer library (OpenSSL flavour) libcurl4-gnutls-dev - development files and documentation for libcurl (GnuTLS flavour) libcurl4-nss-dev - development files and documentation for libcurl (NSS flavour) libcurl4-openssl-dev - development files and documentation for libcurl (OpenSSL flavour) Changes: curl (7.81.0-1ubuntu1.3) jammy-security; urgency=medium . * SECURITY UPDATE: Set-cookie denial of service - debian/patches/CVE-2022-32205.patch: apply limits to cookies specifications in lib/cookie.c, lib/cookie.h, lib/http.c, lib/urldata.h. - CVE-2022-32205 * SECURITY UPDATE: HTTP compression denial of service - debian/patches/CVE-2022-32206.patch: return error on too many compression steps in lib/content_encoding.c. - CVE-2022-32206 * SECURITY UPDATE: Unpreserved file permissions - debian/patches/CVE-2022-32207.patch: add Curl_fopen() for better overwriting of files in lib/Makefile.inc, lib/cookie.c, lib/fopen.c, lib/fopen.h. - CVE-2022-32207 * SECURITY UPDATE: FTP-KRB bad msg verification - debian/patches/CVE-2022-32208.patch: return error properly on decode errors in lib/krb5.c. - CVE-2022-32208 Checksums-Sha1: 074e47f74e44244ab4aa076b3fb24781533a41b4 154656 curl-dbgsym_7.81.0-1ubuntu1.3_arm64.ddeb 26140f7230478d5e1284bbb62850fd7b7948fd26 12891 curl_7.81.0-1ubuntu1.3_arm64.buildinfo 8db399f84546c9a7238b6c196a6af627fa48ffa4 189940 curl_7.81.0-1ubuntu1.3_arm64.deb 59d7054143f24668e982e55b0d3e17d7e71c7321 985154 libcurl3-gnutls-dbgsym_7.81.0-1ubuntu1.3_arm64.ddeb 84768513136ca703e56ccf87b3874de88cf9b843 279130 libcurl3-gnutls_7.81.0-1ubuntu1.3_arm64.deb b1d7f4a8f64d0abdae429a2428cb84185a604d00 1029756 libcurl3-nss-dbgsym_7.81.0-1ubuntu1.3_arm64.ddeb 1fbb09543518bb2bfca9cb8396453f1c43ab6f1c 288046 libcurl3-nss_7.81.0-1ubuntu1.3_arm64.deb 0b0893f4e558474ef1100f7d2deded9aa437f98b 1009784 libcurl4-dbgsym_7.81.0-1ubuntu1.3_arm64.ddeb f461b5235e9814a5aa175578276c120f498a979d 384536 libcurl4-gnutls-dev_7.81.0-1ubuntu1.3_arm64.deb cbeb2e8d7f1c36a8a8b848b471c3c743b0e84b71 393928 libcurl4-nss-dev_7.81.0-1ubuntu1.3_arm64.deb 4c498057d5be43b2cd1d9b1d1a7988621a755473 390306 libcurl4-openssl-dev_7.81.0-1ubuntu1.3_arm64.deb e173ac3f18035779ac633941761e646cf285add0 284398 libcurl4_7.81.0-1ubuntu1.3_arm64.deb Checksums-Sha256: cfa26ea8594177fcd06762d3e6178329629dd1206c6b5ca54baa822a03f57346 154656 curl-dbgsym_7.81.0-1ubuntu1.3_arm64.ddeb 6ce60ea5ff4c947941097428d4496a1a703e0bc40a01da686d61cfeb67610ba7 12891 curl_7.81.0-1ubuntu1.3_arm64.buildinfo 787445b4e8e19b3f502be3c84fdae8243e58479fcccd271d02f281644ccb5b7f 189940 curl_7.81.0-1ubuntu1.3_arm64.deb d9cddc4c8a13d419c047ad8c6fa781a835e597243c56ff7e4196589aeb9e4ddc 985154 libcurl3-gnutls-dbgsym_7.81.0-1ubuntu1.3_arm64.ddeb a23724858445adc88f37ed0e473ea19d94bac58520b9cf5fa0fc472f1b5f288a 279130 libcurl3-gnutls_7.81.0-1ubuntu1.3_arm64.deb fde5be417dbaa1a8859c422bee0adb5fdb47a81cb71a5b295ba26b126c005c2d 1029756 libcurl3-nss-dbgsym_7.81.0-1ubuntu1.3_arm64.ddeb bd5968b34677635337d9e8b78b3e385c2f85241b550707c9f8c809525640bf1f 288046 libcurl3-nss_7.81.0-1ubuntu1.3_arm64.deb df3d7a8d8e2ad5d8fe1cb592b0424e7554129a4772a38443df53d7d4d98374b1 1009784 libcurl4-dbgsym_7.81.0-1ubuntu1.3_arm64.ddeb 033fbbd8ade6ff105c79e553f37411d5925d9752478802e92962bf9f4dc32ea3 384536 libcurl4-gnutls-dev_7.81.0-1ubuntu1.3_arm64.deb 6ec41b27b67fb7421936974b1a0b4768de68ac061ff3e581aefe3015fb98a193 393928 libcurl4-nss-dev_7.81.0-1ubuntu1.3_arm64.deb a19a0e86995828a53d5b02edf30998446debaeebe1b58184b963d3815315c8dd 390306 libcurl4-openssl-dev_7.81.0-1ubuntu1.3_arm64.deb c0b1e70230a3004cdc598b14efa7b695eddcbf55dc29c63c9a58c7902fb0f159 284398 libcurl4_7.81.0-1ubuntu1.3_arm64.deb Files: 7d93215799e2e40bc976a6a38d7a3ddd 154656 debug optional curl-dbgsym_7.81.0-1ubuntu1.3_arm64.ddeb fcf989183969bc65128e07d5f40c6bd8 12891 web optional curl_7.81.0-1ubuntu1.3_arm64.buildinfo 1da8a27e1bc9899cef76622a94ee6504 189940 web optional curl_7.81.0-1ubuntu1.3_arm64.deb 5a7c607b561c8147ba7087e8c0f3dadb 985154 debug optional libcurl3-gnutls-dbgsym_7.81.0-1ubuntu1.3_arm64.ddeb a10f5fa6ce9ce4a5d5e115da41eddbc8 279130 libs optional libcurl3-gnutls_7.81.0-1ubuntu1.3_arm64.deb 284f56435579d8b4a11937c3e16dfe3d 1029756 debug optional libcurl3-nss-dbgsym_7.81.0-1ubuntu1.3_arm64.ddeb eecd9f369a1a39375b030ad7b46031d6 288046 libs optional libcurl3-nss_7.81.0-1ubuntu1.3_arm64.deb 4d93de5ee0d2c7ebb8c1c27c215bd1f7 1009784 debug optional libcurl4-dbgsym_7.81.0-1ubuntu1.3_arm64.ddeb 8f184e142b8b9a3e11d519938372bf95 384536 libdevel optional libcurl4-gnutls-dev_7.81.0-1ubuntu1.3_arm64.deb c0b816d4346fb8f838d181a454bb1089 393928 libdevel optional libcurl4-nss-dev_7.81.0-1ubuntu1.3_arm64.deb 79a6e74abcae8087824b7166af5e4a92 390306 libdevel optional libcurl4-openssl-dev_7.81.0-1ubuntu1.3_arm64.deb bb8b14cfc20e9f5dbeebc3f96d4a8693 284398 libs optional libcurl4_7.81.0-1ubuntu1.3_arm64.deb Original-Maintainer: Alessandro Ghedini