Format: 1.8 Date: Thu, 14 Aug 2014 09:47:32 -0400 Source: serf Binary: libserf-1-1 libserf-dev libserf1-dbg Architecture: powerpc Version: 1.3.3-1ubuntu0.1 Distribution: trusty Urgency: medium Maintainer: Ubuntu Build Daemon Changed-By: Marc Deslauriers Description: libserf-1-1 - high-performance asynchronous HTTP client library libserf-dev - high-performance asynchronous HTTP client library headers libserf1-dbg - high-performance asynchronous HTTP client library debugging symbo Changes: serf (1.3.3-1ubuntu0.1) trusty-security; urgency=medium . * SECURITY UPDATE: cert spoofing via NUL characters in CommonName and SubjectAltNames - debian/patches/CVE-2014-3504.patch: escape null bytes in buckets/ssl_buckets.c. - CVE-2014-3504 * Fix FTBFS because of expired test certs: - debian/patches/expired_certs.patch: switch to test certs from serf 1.3.6. - debian/source/format: switch to 3.0 (quilt) so we can handle the binary cert file - debian/source/include-binaries: include binary cert file from 1.3.6. Checksums-Sha1: 8e85ffd72256139d7493cc878ac398d4ec212b58 37988 libserf-1-1_1.3.3-1ubuntu0.1_powerpc.deb ca239a118039accb31d1ded0d7f7b3dfc8addba5 74190 libserf-dev_1.3.3-1ubuntu0.1_powerpc.deb 3fa9affe601d8c013ded69f926d9e551b484c9ff 105528 libserf1-dbg_1.3.3-1ubuntu0.1_powerpc.deb Checksums-Sha256: d34a4b2a978320936866a965021986a51038d9250889f2e8394b66de8dc3722f 37988 libserf-1-1_1.3.3-1ubuntu0.1_powerpc.deb 7007ff6ebf205cac4f9c4c0e5e81d83c1d4ec6ed2bfc20e7db01fe5cd7f341f4 74190 libserf-dev_1.3.3-1ubuntu0.1_powerpc.deb c26f54de863f8444da943a8edc87b928afb8227d6272c7ffca50220dc4ba8359 105528 libserf1-dbg_1.3.3-1ubuntu0.1_powerpc.deb Files: dcfb9e6c0fd3c79a8479d0dce18ca22c 37988 libs optional libserf-1-1_1.3.3-1ubuntu0.1_powerpc.deb 74e191d6deb9355fc65ead0a7f081c8e 74190 libdevel optional libserf-dev_1.3.3-1ubuntu0.1_powerpc.deb ffc012162bf2c53720dd6f207ef4c7c6 105528 debug extra libserf1-dbg_1.3.3-1ubuntu0.1_powerpc.deb Original-Maintainer: Peter Samuelson