-----BEGIN PGP SIGNED MESSAGE----- Hash: SHA512 Format: 1.8 Date: Tue, 13 Mar 2018 20:47:46 +0000 Source: curl Binary: curl libcurl3 libcurl3-gnutls libcurl3-nss libcurl4-openssl-dev libcurl4-gnutls-dev libcurl4-nss-dev libcurl3-dbg libcurl4-doc Architecture: s390x Version: 7.38.0-4+deb8u10 Distribution: jessie-security Urgency: high Maintainer: s390x Build Daemon (zandonai) Changed-By: Alessandro Ghedini Description: curl - command line tool for transferring data with URL syntax libcurl3 - easy-to-use client-side URL transfer library (OpenSSL flavour) libcurl3-dbg - debugging symbols for libcurl (OpenSSL, GnuTLS and NSS flavours) libcurl3-gnutls - easy-to-use client-side URL transfer library (GnuTLS flavour) libcurl3-nss - easy-to-use client-side URL transfer library (NSS flavour) libcurl4-doc - documentation for libcurl libcurl4-gnutls-dev - development files and documentation for libcurl (GnuTLS flavour) libcurl4-nss-dev - development files and documentation for libcurl (NSS flavour) libcurl4-openssl-dev - development files and documentation for libcurl (OpenSSL flavour) Changes: curl (7.38.0-4+deb8u10) jessie-security; urgency=high . * Fix NIL byte out of bounds write due to FTP path trickery as per CVE-2018-1000120 https://curl.haxx.se/docs/adv_2018-9cd6.html * Fix LDAP NULL pointer dereference as per CVE-2018-1000121 https://curl.haxx.se/docs/adv_2018-97a2.html * Fix RTSP RTP buffer over-read as per CVE-2018-1000122 https://curl.haxx.se/docs/adv_2018-b047.html Checksums-Sha1: c808ee78826e2b9151401c4fa62d37e44f54552e 199230 curl_7.38.0-4+deb8u10_s390x.deb 351707ea6e7044c2a6960ca8b47f7994db8e5c88 252974 libcurl3_7.38.0-4+deb8u10_s390x.deb f1897f789b1cdd8a6200dd8e635da3ce1daa058e 245208 libcurl3-gnutls_7.38.0-4+deb8u10_s390x.deb a27479c54526e9450be71eb3012322e18b4760a3 255930 libcurl3-nss_7.38.0-4+deb8u10_s390x.deb 6e601c04bf8045b49ad80a2d2b06d39a822a5659 332706 libcurl4-openssl-dev_7.38.0-4+deb8u10_s390x.deb 20a8c0e632abc0c1101c33447c5db0523bbd4a33 323750 libcurl4-gnutls-dev_7.38.0-4+deb8u10_s390x.deb cd6107cd91e538df95f95014ae8112a3829a21f0 335642 libcurl4-nss-dev_7.38.0-4+deb8u10_s390x.deb 2fa1bceca1e3f0f1b1f517e810ea8a314620edb6 3670834 libcurl3-dbg_7.38.0-4+deb8u10_s390x.deb Checksums-Sha256: 0b9bde0175ea7db1c004b484c3c7892aa397b4bc56a316e07765a5894626d092 199230 curl_7.38.0-4+deb8u10_s390x.deb 90671d9d7bf3bd7278006ebe5a18e3d6b941c030d8bd4f06d47413dd51b93d76 252974 libcurl3_7.38.0-4+deb8u10_s390x.deb 620e1e02b40104d5604de232ee0032647fdb55a9f812c147f1773e72a674e8fd 245208 libcurl3-gnutls_7.38.0-4+deb8u10_s390x.deb 0c30f3afb4bed3abf6dc810bba946af79a74fc25246d363e0f34087b9f4dfaab 255930 libcurl3-nss_7.38.0-4+deb8u10_s390x.deb 4c53fa20953113dc0cbe10c3da994b2d6ab4fcaab051922f1e7782971b0a5d0d 332706 libcurl4-openssl-dev_7.38.0-4+deb8u10_s390x.deb 43472faf05db2381b0ded4e980a787375d18a48e0de6dffd8b28f5f24eab3919 323750 libcurl4-gnutls-dev_7.38.0-4+deb8u10_s390x.deb 378c510b4ecef413fb3edd9b9392e1f5b9f55579dab6d4a469a7736b6cc03523 335642 libcurl4-nss-dev_7.38.0-4+deb8u10_s390x.deb c85a1b1f222190dde4c54e33d07a8b0cfad5ce4c96055275d59bfca9e5732ff4 3670834 libcurl3-dbg_7.38.0-4+deb8u10_s390x.deb Files: ca87e86e3473ae57bd202e069f947190 199230 web optional curl_7.38.0-4+deb8u10_s390x.deb 95475f47ceae1ad3e039741215613494 252974 libs optional libcurl3_7.38.0-4+deb8u10_s390x.deb 70403878c976ece4d72cf8f9093abc23 245208 libs optional libcurl3-gnutls_7.38.0-4+deb8u10_s390x.deb 70621d4e5f2aad21bb8b510d89a5126b 255930 libs optional libcurl3-nss_7.38.0-4+deb8u10_s390x.deb 2043c5ae7f955535794a24bb613a2873 332706 libdevel optional libcurl4-openssl-dev_7.38.0-4+deb8u10_s390x.deb 6acae9e1b69f6e70d637880ba6ec482e 323750 libdevel optional libcurl4-gnutls-dev_7.38.0-4+deb8u10_s390x.deb d0489c5072fc0996f088dd1a1bdd5b1b 335642 libdevel optional libcurl4-nss-dev_7.38.0-4+deb8u10_s390x.deb c2b5299e53519d9eb8d470171ae88bc1 3670834 debug extra libcurl3-dbg_7.38.0-4+deb8u10_s390x.deb -----BEGIN PGP SIGNATURE----- iQIzBAEBCgAdFiEEZIVHsxgKd8iwU//OW0Rd05qVpNMFAlqoYqIACgkQW0Rd05qV pNOZzA//Z4GoUgrNUPy7e7nQMBCpM1L7FAYGiQrN2MHJ+vwZ2dwgGtD3vZ1rAKcA x1iWuUyiAtlGA3CrGVP2pB4wmhWSEkLGwVdX40N7l/5KHigjng5IujfJB0AKs9BB 090CbtzUOx+V1cEhwTtx46iQZAVK2zQ9aYLqurrPt1k3cQX3CRSlhGr5AFYqjYp2 zZY2if8/VB82v9CLusK5qhaeLJEWM3Ed1uwZnnsrwoGYnHGu0hNvD5NZwfotIEVp dtb8RZ5lDFAsIIC9AIBJ3Li5cZGpDzpCF825wwofpTtJ2tdDEDCSiNo8cq+/5R+7 QV9sFP82vXzT2vCs8zs6GG1x0OaoxBAGGtWIPXb2xJobjM+vzrCNIMMkG+iVyMpF E7CsZUPbsSKThzfG8hg8a02mzi8P3fkxnSDfumUcmsmKhhfWY1jkBO4w8Vs+4GER +CyCMg3LC9ez5kOsZh0E0SlCyVM+iiwgN3VIFxQ3p/An+5qFsGMCoOkMURybLyEv AANbMNpl3ShEFKpT+WlwyIvxu2XsS5n+kC2wj7IQ7NC2m1TOEf9TCFtaJLy835gt L45tS5ry4PSv6sV0H0+UDAutXqHZ6eYXCyFffan79ETJ2EbjdnYYkNCLZQN+/28w Oson9zionzZ9NwNbkpQLNTl4NfwHVD9KcLfzwSZMSn4Ajb/eO2o= =d8KL -----END PGP SIGNATURE-----