Format: 1.8 Date: Mon, 17 Jul 2023 07:53:10 -0400 Source: curl Binary: curl libcurl3-gnutls libcurl3-nss libcurl4 libcurl4-gnutls-dev libcurl4-nss-dev libcurl4-openssl-dev Built-For-Profiles: noudeb Architecture: arm64 Version: 7.88.1-8ubuntu2.1 Distribution: lunar Urgency: medium Maintainer: Launchpad Build Daemon Changed-By: Marc Deslauriers Description: curl - command line tool for transferring data with URL syntax libcurl3-gnutls - easy-to-use client-side URL transfer library (GnuTLS flavour) libcurl3-nss - easy-to-use client-side URL transfer library (NSS flavour) libcurl4 - easy-to-use client-side URL transfer library (OpenSSL flavour) libcurl4-gnutls-dev - development files and documentation for libcurl (GnuTLS flavour) libcurl4-nss-dev - development files and documentation for libcurl (NSS flavour) libcurl4-openssl-dev - development files and documentation for libcurl (OpenSSL flavour) Changes: curl (7.88.1-8ubuntu2.1) lunar-security; urgency=medium . * SECURITY UPDATE: improper certificate validation vulnerability - debian/patches/CVE-2023-28321.patch: fix host name wildcard checking in lib/vtls/hostcheck.c, tests/data/test1397, tests/unit/unit1397.c. - CVE-2023-28321 * SECURITY UPDATE: information disclosure vulnerability - debian/patches/CVE-2023-28322.patch: unify the upload/method handling in lib/curl_rtmp.c, lib/file.c, lib/ftp.c, lib/http.c, lib/imap.c, lib/rtsp.c, lib/setopt.c, lib/smb.c, lib/smtp.c, lib/tftp.c, lib/transfer.c, lib/urldata.h, lib/vssh/libssh.c, lib/vssh/libssh2.c, lib/vssh/wolfssh.c. - CVE-2023-28322 * SECURITY UPDATE: fopen race condition - debian/patches/CVE-2023-32001.patch: fix race in lib/fopen.c. - CVE-2023-32001 Checksums-Sha1: 8a8ca7fc32b7e80259335be26b5dc4b277b5e737 165350 curl-dbgsym_7.88.1-8ubuntu2.1_arm64.ddeb 7bda0233bd1de3a5c77dbd2de1d8191ee3c22e2b 12904 curl_7.88.1-8ubuntu2.1_arm64.buildinfo b54600673c089d3a9914f2ca73c4acff1f27cdb8 206168 curl_7.88.1-8ubuntu2.1_arm64.deb 39393678ca150544e309b799a55e7082e08096a6 1059980 libcurl3-gnutls-dbgsym_7.88.1-8ubuntu2.1_arm64.ddeb 3b12d18adf907d2155c8ae82969e25eef4987d1f 292892 libcurl3-gnutls_7.88.1-8ubuntu2.1_arm64.deb 2668c850cd0da1bb9fdfe8723caf10e5bccbd7d7 1106680 libcurl3-nss-dbgsym_7.88.1-8ubuntu2.1_arm64.ddeb 90a563cb83ef933da767e4e7379cf935c72a15c5 302984 libcurl3-nss_7.88.1-8ubuntu2.1_arm64.deb 37f59c3dedfbf12c5d4338d253ffdc2e9b32b656 1087630 libcurl4-dbgsym_7.88.1-8ubuntu2.1_arm64.ddeb 0c2460b278f1e1cd84b5bc5a9e06cb6bd66fb6f3 406364 libcurl4-gnutls-dev_7.88.1-8ubuntu2.1_arm64.deb 8d3f48f9ebc6b38d5e9cf98b5353444c0d7f4439 417150 libcurl4-nss-dev_7.88.1-8ubuntu2.1_arm64.deb d7cfaa5414d10629f898658d33f9799249ae4214 411656 libcurl4-openssl-dev_7.88.1-8ubuntu2.1_arm64.deb ee7d4581898d5e59be4699021d5540fb90198c12 299018 libcurl4_7.88.1-8ubuntu2.1_arm64.deb Checksums-Sha256: 28ef1e2109ee38c9fa57b4eb43039f2987621cc8a635a4d2a8b1a725154cbb41 165350 curl-dbgsym_7.88.1-8ubuntu2.1_arm64.ddeb c613ea2a8a84cd08deae53b331be6b1538ae0bf7ca952506de16832f35c764f1 12904 curl_7.88.1-8ubuntu2.1_arm64.buildinfo bd2f1d54fdbd1cc8237ac24bba5207457343db90df6954749f0776615f8ef203 206168 curl_7.88.1-8ubuntu2.1_arm64.deb 3d60bb0b4a13f4168a99cbefc9cb82a277d4b0643cd9f70ff73c5dc9ac842e10 1059980 libcurl3-gnutls-dbgsym_7.88.1-8ubuntu2.1_arm64.ddeb bc2a7c5f63a79a2931ce69fc078e3d407047bc428be0e8248b59c32b88152071 292892 libcurl3-gnutls_7.88.1-8ubuntu2.1_arm64.deb ebb02836b54273d86bc63c6522065b058686b4fd3892af5b57bac0d8776a3205 1106680 libcurl3-nss-dbgsym_7.88.1-8ubuntu2.1_arm64.ddeb 26a107374764be6c437ee405fbb11e2514084cf8868e21f138daf575df204ea8 302984 libcurl3-nss_7.88.1-8ubuntu2.1_arm64.deb 0b06e99a68388bc38d54b5600831bd3ea394513b39a24718e3519f2f62fcbbe1 1087630 libcurl4-dbgsym_7.88.1-8ubuntu2.1_arm64.ddeb 24a4fcadeda3fc74733185ecfc1e9e732fa4e6b332689d181eed66ada49a7aa6 406364 libcurl4-gnutls-dev_7.88.1-8ubuntu2.1_arm64.deb 8770e1374e5766dc163e796186c1fc6a4a4d908a120bfb6b16421bf0346df7d2 417150 libcurl4-nss-dev_7.88.1-8ubuntu2.1_arm64.deb defb1bfda9e68a47016440a43f1ca954879fdc568faac360bf87e604a062e5d5 411656 libcurl4-openssl-dev_7.88.1-8ubuntu2.1_arm64.deb 48df88c97ced96110f47c1a56392d21014b5c729be1682915c7fc101a369456f 299018 libcurl4_7.88.1-8ubuntu2.1_arm64.deb Files: e60a2cfad9cc8dd9585db5751d8d1023 165350 debug optional curl-dbgsym_7.88.1-8ubuntu2.1_arm64.ddeb ef8c606814a5cbc0adef9e6d58e09702 12904 web optional curl_7.88.1-8ubuntu2.1_arm64.buildinfo 0eb529458f0b2260a2f0ddfe68f54b45 206168 web optional curl_7.88.1-8ubuntu2.1_arm64.deb 8543913c5bd5ee981faa2393349787b9 1059980 debug optional libcurl3-gnutls-dbgsym_7.88.1-8ubuntu2.1_arm64.ddeb 486a43a71692ccdc64c480daa9174342 292892 libs optional libcurl3-gnutls_7.88.1-8ubuntu2.1_arm64.deb 26e0bf4bd0c24eaf466965c6861f101d 1106680 debug optional libcurl3-nss-dbgsym_7.88.1-8ubuntu2.1_arm64.ddeb 704d8f1340186a23eaf47dc4d3a60686 302984 libs optional libcurl3-nss_7.88.1-8ubuntu2.1_arm64.deb 16f3bddb17eabecbf119172263adce0f 1087630 debug optional libcurl4-dbgsym_7.88.1-8ubuntu2.1_arm64.ddeb 17d1024dc2d0c0d2ef8eba05f901f603 406364 libdevel optional libcurl4-gnutls-dev_7.88.1-8ubuntu2.1_arm64.deb 7815886e16d3876cc2dcdb0f0d4d4f46 417150 libdevel optional libcurl4-nss-dev_7.88.1-8ubuntu2.1_arm64.deb 48f9972971528e317d124d8f4f62458c 411656 libdevel optional libcurl4-openssl-dev_7.88.1-8ubuntu2.1_arm64.deb eba70770586ee508ed92da7f07f0c25e 299018 libs optional libcurl4_7.88.1-8ubuntu2.1_arm64.deb Original-Maintainer: Alessandro Ghedini