-----BEGIN PGP SIGNED MESSAGE----- Hash: SHA512 Format: 1.8 Date: Thu, 25 Jan 2018 22:34:49 +0000 Source: curl Binary: curl libcurl3 libcurl3-gnutls libcurl3-nss libcurl4-openssl-dev libcurl4-gnutls-dev libcurl4-nss-dev libcurl3-dbg libcurl4-doc Architecture: i386 Version: 7.38.0-4+deb8u9 Distribution: jessie-security Urgency: high Maintainer: amd64 Build Daemon (binet) Changed-By: Alessandro Ghedini Description: curl - command line tool for transferring data with URL syntax libcurl3 - easy-to-use client-side URL transfer library (OpenSSL flavour) libcurl3-dbg - debugging symbols for libcurl (OpenSSL, GnuTLS and NSS flavours) libcurl3-gnutls - easy-to-use client-side URL transfer library (GnuTLS flavour) libcurl3-nss - easy-to-use client-side URL transfer library (NSS flavour) libcurl4-doc - documentation for libcurl libcurl4-gnutls-dev - development files and documentation for libcurl (GnuTLS flavour) libcurl4-nss-dev - development files and documentation for libcurl (NSS flavour) libcurl4-openssl-dev - development files and documentation for libcurl (OpenSSL flavour) Changes: curl (7.38.0-4+deb8u9) jessie-security; urgency=high . * Fix HTTP authentication leak in redirects as per CVE-2018-1000007 https://curl.haxx.se/docs/adv_2018-b3bf.html Checksums-Sha1: ecd08e0749b413d431742128f435551bf1bbe7dc 203128 curl_7.38.0-4+deb8u9_i386.deb 9cf21ad6d4b5b0dbef3e39cf19c0c3a9de5a6ba1 279538 libcurl3_7.38.0-4+deb8u9_i386.deb 4ecc63f1a3455617e90ced2ea89b210666efcb48 270474 libcurl3-gnutls_7.38.0-4+deb8u9_i386.deb 7d470eeacbaf57cd518b95339e60f86aef51bf1c 282098 libcurl3-nss_7.38.0-4+deb8u9_i386.deb bdd8e276411a48228dfc649f3b9e69dbaeef5081 361404 libcurl4-openssl-dev_7.38.0-4+deb8u9_i386.deb ba2d0e42097f2ac2af0a11d81a1acc1fb67ebed3 351728 libcurl4-gnutls-dev_7.38.0-4+deb8u9_i386.deb 42610bd1ee630ae56a88ef52d699034ad4eb4508 365068 libcurl4-nss-dev_7.38.0-4+deb8u9_i386.deb 4d57cadb839ef17e3d64adedf87afb4e413ce89f 3139902 libcurl3-dbg_7.38.0-4+deb8u9_i386.deb Checksums-Sha256: 8eee2c1ac1b189c04aef742c7a15aa1af443d27f5160e24573d482e8b42c89a4 203128 curl_7.38.0-4+deb8u9_i386.deb e7472b2acbdf90d6b6f53c4ab4fef26b1e7544c5460b6ede28d9a55d219a7175 279538 libcurl3_7.38.0-4+deb8u9_i386.deb 81d5283010c199caba86249f57e394f60c3f0f058415a8bd8092523e5c737240 270474 libcurl3-gnutls_7.38.0-4+deb8u9_i386.deb c7cbcdd4a70e3054eea3877fc9af2fa726c66a1ff0b23373f7aafb01778a0fd3 282098 libcurl3-nss_7.38.0-4+deb8u9_i386.deb 75a5b341522f6e1ada75b980bc401dc6d13c5c2b019b0e73c899d53c1b985237 361404 libcurl4-openssl-dev_7.38.0-4+deb8u9_i386.deb 9714f9944bafd542197e60f576d9fbf4c50b0a06888064e33cc6267d5e886119 351728 libcurl4-gnutls-dev_7.38.0-4+deb8u9_i386.deb 734464b7c24c82c8a84fa9f9b0e57f0b81ff60aa2bd5b0d1bd5c9a297d886437 365068 libcurl4-nss-dev_7.38.0-4+deb8u9_i386.deb 396907756815493db7c542a999622d244030b4f26c3bc46e25a49887b195193b 3139902 libcurl3-dbg_7.38.0-4+deb8u9_i386.deb Files: a2977615f1884a1456a5402eacee8551 203128 web optional curl_7.38.0-4+deb8u9_i386.deb f6c0f6b7a6af1b05e90dbd89ea2ed539 279538 libs optional libcurl3_7.38.0-4+deb8u9_i386.deb 638cac8b7db76c68b3ef0154f4e5d3a1 270474 libs optional libcurl3-gnutls_7.38.0-4+deb8u9_i386.deb a1b1c360c574e474962c6034fb5d6400 282098 libs optional libcurl3-nss_7.38.0-4+deb8u9_i386.deb c6229370b830652723ee2ca0f9ec7f50 361404 libdevel optional libcurl4-openssl-dev_7.38.0-4+deb8u9_i386.deb dc3a4147bbbfa44e682e911c125e2bb5 351728 libdevel optional libcurl4-gnutls-dev_7.38.0-4+deb8u9_i386.deb f4400a47da9efc44a3f159498b872ed5 365068 libdevel optional libcurl4-nss-dev_7.38.0-4+deb8u9_i386.deb 28e21c3b41fce42728a3cdbcdd29bf58 3139902 debug extra libcurl3-dbg_7.38.0-4+deb8u9_i386.deb -----BEGIN PGP SIGNATURE----- iQIzBAEBCgAdFiEEyT9Sp5Gew/rj3m7114gF3mj51YMFAlpqiWkACgkQ14gF3mj5 1YNMWRAAnH9dhXQGxPxKOWB4gLpwPaDV4HexBJU5XF6RA0rVdFP5M7+eAoWkC/ZZ XXdvE4nZSZEKz0B431PFuFWbpiTZoCTnXr0C6/mah0U/aCCYbZJKVFozXApxRfv6 nk/VtqXOifBBigLiwHPwRVUHh2yAEfFl5LFjukjngctA1lk4hsSLfZPr+MVzvkGi RM7s7SJ5AqVYrrzQZmR/kBoHi0SQrquwo9zFrGahfmfg/30PsMWgwUXV1Zp2xGe2 DWVMVnv20hW7uQ7sOgnG6ePWYomn2gSGQ9slaD0YTtpUQ7GEMsed+Wimhgteu5HG jlhImW3LzKEihvc6qE9ff5mZgMJPL8I5KwLhz02IHPtO9Calg2/8QrQet7gEg4JE 7li7iSJ7gbfu9UHv6LTNNVB4Yw3Hq+tYir/SIt4SPN66j1KWaDnfpqa0TYRjyUw4 TptPAqhZ1k4U1kCtqdHQByMde68y2b1ERQMqKJLwruzYvSNhHU4l6eq0mHKZ/M4C ZOWAOSdCtFAWG5832/UqqKHkcIqxAXXiFKI1166jDEKjKCDAZdDT+bbfXHrFX23L UBy9T2tOlBJxVvqYAOKtzeh5IfaK7hw9PloRlB470J0zypWdUQ4GJHclqi5fJ1E6 ZX4XF5UvpAE0LGcrN+nIJvbXM+qKF9u0+edpJqkx/g/e/RAKXkA= =aIkD -----END PGP SIGNATURE-----