-----BEGIN PGP SIGNED MESSAGE----- Hash: SHA512 Format: 1.8 Date: Tue, 13 Mar 2018 20:47:46 +0000 Source: curl Binary: curl libcurl3 libcurl3-gnutls libcurl3-nss libcurl4-openssl-dev libcurl4-gnutls-dev libcurl4-nss-dev libcurl3-dbg libcurl4-doc Architecture: armel Version: 7.38.0-4+deb8u10 Distribution: jessie-security Urgency: high Maintainer: armhf Build Daemon (henze) Changed-By: Alessandro Ghedini Description: curl - command line tool for transferring data with URL syntax libcurl3 - easy-to-use client-side URL transfer library (OpenSSL flavour) libcurl3-dbg - debugging symbols for libcurl (OpenSSL, GnuTLS and NSS flavours) libcurl3-gnutls - easy-to-use client-side URL transfer library (GnuTLS flavour) libcurl3-nss - easy-to-use client-side URL transfer library (NSS flavour) libcurl4-doc - documentation for libcurl libcurl4-gnutls-dev - development files and documentation for libcurl (GnuTLS flavour) libcurl4-nss-dev - development files and documentation for libcurl (NSS flavour) libcurl4-openssl-dev - development files and documentation for libcurl (OpenSSL flavour) Changes: curl (7.38.0-4+deb8u10) jessie-security; urgency=high . * Fix NIL byte out of bounds write due to FTP path trickery as per CVE-2018-1000120 https://curl.haxx.se/docs/adv_2018-9cd6.html * Fix LDAP NULL pointer dereference as per CVE-2018-1000121 https://curl.haxx.se/docs/adv_2018-97a2.html * Fix RTSP RTP buffer over-read as per CVE-2018-1000122 https://curl.haxx.se/docs/adv_2018-b047.html Checksums-Sha1: fd04d8fd8c4ef5c335f289ba0c60728794156a3d 196548 curl_7.38.0-4+deb8u10_armel.deb c02d99f040526ba02b08db4648d75370a83548ce 232974 libcurl3_7.38.0-4+deb8u10_armel.deb 6013a7250218a58eb1129e0e58620a3c4985f1dd 225764 libcurl3-gnutls_7.38.0-4+deb8u10_armel.deb a025e30f832c5824085b85c4f94e93f747a4eeeb 236102 libcurl3-nss_7.38.0-4+deb8u10_armel.deb bf8e2536ba928478020e7f07c2b37d0f7c454cc4 316950 libcurl4-openssl-dev_7.38.0-4+deb8u10_armel.deb 7b5229442bfe24aef1974bf91b56cbc14a96708c 308914 libcurl4-gnutls-dev_7.38.0-4+deb8u10_armel.deb 2da3b2d81fea1d0e9cf421a9f03e83016d73e86a 320520 libcurl4-nss-dev_7.38.0-4+deb8u10_armel.deb 5ee4f3ea792d3d2aa6721a2e7fa170845613e73c 3572292 libcurl3-dbg_7.38.0-4+deb8u10_armel.deb Checksums-Sha256: 96428fa3feab95d7cb9fbf4c9a2cd19b62833e4bfac32d5d31a9f3ad3ebb6735 196548 curl_7.38.0-4+deb8u10_armel.deb 5b68527c4c6350b64e1821a61fa415d45e60664f9c64e60a7a304369f64b4353 232974 libcurl3_7.38.0-4+deb8u10_armel.deb 7c2aaac28744e76e8354893baa23a4eab2c678d258cbba0404b928a84c41978e 225764 libcurl3-gnutls_7.38.0-4+deb8u10_armel.deb 5bb7a791c0742c52825ccfc663aa8f9502d5d2ace54e910e82a25e9f7c8efc9a 236102 libcurl3-nss_7.38.0-4+deb8u10_armel.deb 82ecbf0efb8db1714f55f1269cc77c2d068544d4025948bf4a38af6bd75a47ba 316950 libcurl4-openssl-dev_7.38.0-4+deb8u10_armel.deb c5d1f14bcc6c9ea33891841bb85451c076834869a630b944ac4c709f4cb39613 308914 libcurl4-gnutls-dev_7.38.0-4+deb8u10_armel.deb 114da9442a5fef88bd0ef09fda820ff87d3a2b3abccaa7d500ec96d2b22dc696 320520 libcurl4-nss-dev_7.38.0-4+deb8u10_armel.deb 7c018f8860ac9292d46deca8b36928f42e6ad619a4ca273760be270d93ded0a0 3572292 libcurl3-dbg_7.38.0-4+deb8u10_armel.deb Files: 2fb86619db8cfa6a300948d952a85714 196548 web optional curl_7.38.0-4+deb8u10_armel.deb b8f97798af53d888aebae7c7da54b0c3 232974 libs optional libcurl3_7.38.0-4+deb8u10_armel.deb 2e1e4b6264f578c736af6fff5cd0c4a9 225764 libs optional libcurl3-gnutls_7.38.0-4+deb8u10_armel.deb 7da9f74eef2e6fe34315779581fa30f7 236102 libs optional libcurl3-nss_7.38.0-4+deb8u10_armel.deb a3bc67cbd7fbb79e1c08e773fee76f87 316950 libdevel optional libcurl4-openssl-dev_7.38.0-4+deb8u10_armel.deb d85a92ead59a42b2d3f1ec20069d4703 308914 libdevel optional libcurl4-gnutls-dev_7.38.0-4+deb8u10_armel.deb a05e9ad2955c61b19e36bf59f0274a3a 320520 libdevel optional libcurl4-nss-dev_7.38.0-4+deb8u10_armel.deb 8915573f4d7f266daeea33988f104f24 3572292 debug extra libcurl3-dbg_7.38.0-4+deb8u10_armel.deb -----BEGIN PGP SIGNATURE----- iQIzBAEBCgAdFiEEBElFh63JZapmYjreupsCjku36ToFAlqobPsACgkQupsCjku3 6TqIfQ//fvVFp8nQopqCCmlcUBESnvuRLcH8ehMGWw8268DqjfDsIgEFOzLO3ggw atiQlIwCf+FUlnkWshVm0UvQK4gDCb02zkQLffLDvq2+KrZn6j/4V3vXM4yPvUUc xi5Swb6H8vawncsgYnwyWmt17/NsgBSChusORS6UlzDHYg/WSQgvSlaoK1d2MbDQ UeTvPlS3oqexpViyNsNYUXCsU00Vlh5ubjZFBMudG2I9hjRt7ZH7X2+h8w+rSJfJ r9i+7Z4+nz2x6eU1R4rL8ussReqsIEMvqYtud9S3Gos4jFK9IZ9FW0OnUP2A3VtL kygClgCNzn/t6mUuIvXNWaBGaMqghpHVI93asf+wxMv8g1XC3/RQJpmQtJgjh79t cCkd2wtJecf3eFfE/kT6t4+RqnlGzXWdzqBcwgGN/qI3BqD00IWDUcYoVb6c4DOV VOIvX8lEhFqxdEe9EVIPF23WchK62J6HrCgtSvd5UeUrvS0nbksBtiayX8PpXyiu UPgb/XJuWpoeRHUTCA8D9f6fkUBkFpPKZdl3dfR8KxNAQcHgdwXTnZP2ZyKPlNRF s4zzFKg8GKXNBS7K5TMpXyUnVTf7VuB03hl4uGCzSizULHLaFFqQA11sjw5CsAOb GRPBXhwcrW8DhkqM9PdHRBMV+jR3NJPXQrsVytwOU0wg6R/4qcU= =k0AS -----END PGP SIGNATURE-----