-----BEGIN PGP SIGNED MESSAGE----- Hash: SHA512 Format: 1.8 Date: Tue, 13 Mar 2018 20:47:46 +0000 Source: curl Binary: curl libcurl3 libcurl3-gnutls libcurl3-nss libcurl4-openssl-dev libcurl4-gnutls-dev libcurl4-nss-dev libcurl3-dbg libcurl4-doc Architecture: armhf Version: 7.38.0-4+deb8u10 Distribution: jessie-security Urgency: high Maintainer: armhf Build Daemon (hasse) Changed-By: Alessandro Ghedini Description: curl - command line tool for transferring data with URL syntax libcurl3 - easy-to-use client-side URL transfer library (OpenSSL flavour) libcurl3-dbg - debugging symbols for libcurl (OpenSSL, GnuTLS and NSS flavours) libcurl3-gnutls - easy-to-use client-side URL transfer library (GnuTLS flavour) libcurl3-nss - easy-to-use client-side URL transfer library (NSS flavour) libcurl4-doc - documentation for libcurl libcurl4-gnutls-dev - development files and documentation for libcurl (GnuTLS flavour) libcurl4-nss-dev - development files and documentation for libcurl (NSS flavour) libcurl4-openssl-dev - development files and documentation for libcurl (OpenSSL flavour) Changes: curl (7.38.0-4+deb8u10) jessie-security; urgency=high . * Fix NIL byte out of bounds write due to FTP path trickery as per CVE-2018-1000120 https://curl.haxx.se/docs/adv_2018-9cd6.html * Fix LDAP NULL pointer dereference as per CVE-2018-1000121 https://curl.haxx.se/docs/adv_2018-97a2.html * Fix RTSP RTP buffer over-read as per CVE-2018-1000122 https://curl.haxx.se/docs/adv_2018-b047.html Checksums-Sha1: 95f2fb5b433c2618a2380d9e1c2e05fefcbadf9b 196512 curl_7.38.0-4+deb8u10_armhf.deb 43a054bc10750c9ca1afbd7dd32a34043a270c5b 236028 libcurl3_7.38.0-4+deb8u10_armhf.deb 32afe4649b0cb83ca19d8ab17cfb3d9399df7f8d 229270 libcurl3-gnutls_7.38.0-4+deb8u10_armhf.deb 015f0604f5039b58407d25568bfccf3cc7e3ef68 239074 libcurl3-nss_7.38.0-4+deb8u10_armhf.deb 85f6384fb87bde7d6b324b38bd30946d61230565 315834 libcurl4-openssl-dev_7.38.0-4+deb8u10_armhf.deb 482bbbda129aa0ed10d37e7378d3feb92d07176d 307674 libcurl4-gnutls-dev_7.38.0-4+deb8u10_armhf.deb 36fc788fa19c1f9cb8ffb1067a0208ec74b496d0 319150 libcurl4-nss-dev_7.38.0-4+deb8u10_armhf.deb 3837c55ec396ed07db6006b41059e260b56e7566 3573200 libcurl3-dbg_7.38.0-4+deb8u10_armhf.deb Checksums-Sha256: e7c08193b31c3c3e6027fec9ac5d25174f112d4529b29c665c161715ea5c5b9a 196512 curl_7.38.0-4+deb8u10_armhf.deb 5555489ea17a731bc6e51afec7126ea376ed3f3157bec55bb8d74d0c77480b8a 236028 libcurl3_7.38.0-4+deb8u10_armhf.deb 6c2f062333cb8d5c5e38452161f50c4bf878b31c1cb747c6d13ca9f112f65812 229270 libcurl3-gnutls_7.38.0-4+deb8u10_armhf.deb 840f8df1b1b68d943884fe2ac31b69ad9589a5e1509ecb880d3d26e2d0210022 239074 libcurl3-nss_7.38.0-4+deb8u10_armhf.deb af2514c01e472f7265d316313ba3fb1942da46bf635ab2a4c21351cde4182afa 315834 libcurl4-openssl-dev_7.38.0-4+deb8u10_armhf.deb 0e5ad3050f6b680550570e2ea350468bea5d651d74dfe5c0c8d9b297bf3f3013 307674 libcurl4-gnutls-dev_7.38.0-4+deb8u10_armhf.deb a4762b14841bf3fe6f9053d02b8e7a14d96c2f0d747f83a5b5f1215cfe0f6646 319150 libcurl4-nss-dev_7.38.0-4+deb8u10_armhf.deb d3ce0e5a4fe8cba4d5ae77cc1d3e284ba24b83d260a708739809e1dd2d9b0b98 3573200 libcurl3-dbg_7.38.0-4+deb8u10_armhf.deb Files: 6d861ef35e7d73769fbcc0759571551b 196512 web optional curl_7.38.0-4+deb8u10_armhf.deb 73a4ebf4efbeea2798ca16b63b19897c 236028 libs optional libcurl3_7.38.0-4+deb8u10_armhf.deb 98191c871a3bcf588c36c488121c00f4 229270 libs optional libcurl3-gnutls_7.38.0-4+deb8u10_armhf.deb 51e12d4846be9a22c99d9eb41426df5e 239074 libs optional libcurl3-nss_7.38.0-4+deb8u10_armhf.deb aa2f3e4913ae9061bfe57b711bd4e996 315834 libdevel optional libcurl4-openssl-dev_7.38.0-4+deb8u10_armhf.deb a671ab6e3676c2e7704a1394a81cc1dd 307674 libdevel optional libcurl4-gnutls-dev_7.38.0-4+deb8u10_armhf.deb 5018f16361ccb8965506a619af4f32d7 319150 libdevel optional libcurl4-nss-dev_7.38.0-4+deb8u10_armhf.deb 86bb36c467d54353cc3da4a6631357e4 3573200 debug extra libcurl3-dbg_7.38.0-4+deb8u10_armhf.deb -----BEGIN PGP SIGNATURE----- iQIzBAEBCgAdFiEEOrpcz1zz6XfVhIpSrHCByDH/tj8FAlqobRwACgkQrHCByDH/ tj8hZRAAsIv8jdmtq2XS3awyogou5xXL64PK9R7lrShMjfip8cSmNpBW9/roqwJR l5F4kJn7Q5vpb9u/oUkbtIympuSoRk1lj9sNSCBo64qcnmLFeOUAmyxGd8+BRif2 9s3ENBjTjzNfI7wNV86Wb7sAMlOXHeRLJs+NURxWsE2zqvcITXubwPPkdK3JV0+b 6Dci3Q7bdzxIq5fPIpbL+bI2q5k6VpJqI5tXONnGGLZYLYyrSr8ACSd+LtiGOsyb M7TwyXSY8hdAJtbG2Y1HWe2CamY4Ef3zMC2HKYpp49a3m6URUSaNT3QOlEHmX4R5 RYuaRqHQjWH+5aRrRrlm/sRb7hIYlpI5bP6UrQeWt+MRTu9e6uiqRAOFizIVfHOn rwJRi4TtJLosB0GfxnFIBbhdxD1fiZVFXVnI4SbW+wxMIJfwswhA3girhqkVRQ3z +04/NwvRE1mCSqtSzkTZCJa+rUIGq6QsIbbeWryr4/4sAvOgFpeqpqypI0RY8C50 jhqy7AnIHP4gDRb7cKs4d5kZeeXjcJlhNUSm2dj7pr0x8MTVbZ1DJNkj/MiGafFs drRN+/wy3OkSuadxPD0mQXdCiHsPzKh+Ez+39MpSeGh97Zi4rGOERXGq1FNddtv+ 5+erbnhdaX+lkQOFCb+gCEveI0TkKBWDFgjqTnCpi1oEjumlEUI= =ZD2M -----END PGP SIGNATURE-----