-----BEGIN PGP SIGNED MESSAGE----- Hash: SHA512 Format: 1.8 Date: Tue, 13 Mar 2018 00:46:06 +0000 Source: curl Binary: curl libcurl3 libcurl3-gnutls libcurl3-nss libcurl4-openssl-dev libcurl4-gnutls-dev libcurl4-nss-dev libcurl3-dbg libcurl4-doc Architecture: armel Version: 7.52.1-5+deb9u5 Distribution: stretch-security Urgency: high Maintainer: armhf Build Daemon (antheil) Changed-By: Alessandro Ghedini Description: curl - command line tool for transferring data with URL syntax libcurl3 - easy-to-use client-side URL transfer library (OpenSSL flavour) libcurl3-dbg - debugging symbols for libcurl (OpenSSL, GnuTLS and NSS flavours) libcurl3-gnutls - easy-to-use client-side URL transfer library (GnuTLS flavour) libcurl3-nss - easy-to-use client-side URL transfer library (NSS flavour) libcurl4-doc - documentation for libcurl libcurl4-gnutls-dev - development files and documentation for libcurl (GnuTLS flavour) libcurl4-nss-dev - development files and documentation for libcurl (NSS flavour) libcurl4-openssl-dev - development files and documentation for libcurl (OpenSSL flavour) Changes: curl (7.52.1-5+deb9u5) stretch-security; urgency=high . * Fix NIL byte out of bounds write due to FTP path trickery as per CVE-2018-1000120 https://curl.haxx.se/docs/adv_2018-9cd6.html * Fix LDAP NULL pointer dereference as per CVE-2018-1000121 https://curl.haxx.se/docs/adv_2018-97a2.html * Fix RTSP RTP buffer over-read as per CVE-2018-1000122 https://curl.haxx.se/docs/adv_2018-b047.html Checksums-Sha1: aebec1a8c524cfbc56b6d091019dc5e4368c0e4c 128830 curl-dbgsym_7.52.1-5+deb9u5_armel.deb df645a99b902888ee6c34536da0d8fcd644728ce 10318 curl_7.52.1-5+deb9u5_armel.buildinfo 806b9f1644fd4e1b2f142633c6049ce614ec42f9 223534 curl_7.52.1-5+deb9u5_armel.deb 99f0147cea7630633cbea05c1fbbdda57e01de56 4936140 libcurl3-dbg_7.52.1-5+deb9u5_armel.deb b8a9d25887c9432d9f26956f843d6cf22dea3233 259722 libcurl3-gnutls_7.52.1-5+deb9u5_armel.deb bdff021498af9acbc430a73e217418f8c616c598 264830 libcurl3-nss_7.52.1-5+deb9u5_armel.deb b2c9080fe0c810b0a32455fcb95cb41f21914db1 260856 libcurl3_7.52.1-5+deb9u5_armel.deb a479a64c2ea236ee134c0676e5c1bf4c667d267f 351774 libcurl4-gnutls-dev_7.52.1-5+deb9u5_armel.deb 2b630c9625a1dedbb84d5b593d9753a620d1b867 357594 libcurl4-nss-dev_7.52.1-5+deb9u5_armel.deb cef9b4698c640a0f625ed5af252e402b39d2477b 353366 libcurl4-openssl-dev_7.52.1-5+deb9u5_armel.deb Checksums-Sha256: 4fdc5b34859fa0ae4265b1bb9ebe7627fd42484244e2108b25224728f0f6aba9 128830 curl-dbgsym_7.52.1-5+deb9u5_armel.deb 96c73cae140eed0db8b6dfb980d0d271513910551dc8964fa642b06969f619fe 10318 curl_7.52.1-5+deb9u5_armel.buildinfo 95c866ac9fb5ea2a2d3d696f515fd28bb4c9d572b2a77c8de291ac376049fa0e 223534 curl_7.52.1-5+deb9u5_armel.deb 33fdc6eb7c24a2305c259a9e06a321be4a50db5fc235f242fd3e20800e785e55 4936140 libcurl3-dbg_7.52.1-5+deb9u5_armel.deb f4b56d0506c47e60a41b41262fd99baa03738731efc6cb2aef67854e62113358 259722 libcurl3-gnutls_7.52.1-5+deb9u5_armel.deb 10833baf6cb7af8629a02cb2dc3162ed49efc5cdce498afbf49f4072a70f31ca 264830 libcurl3-nss_7.52.1-5+deb9u5_armel.deb 075de6bbb7a32caa91b08b867b3a080be9d7e4b5a3052f2ab92afaeba612b70e 260856 libcurl3_7.52.1-5+deb9u5_armel.deb be8e1cfcb87bf643330eeba73474d478d6939171780fef550763a2fadfca0c87 351774 libcurl4-gnutls-dev_7.52.1-5+deb9u5_armel.deb 3a11f94bd8f359f549bcd9b2b130c96940448c5c849f91eaa61a67f617d005e7 357594 libcurl4-nss-dev_7.52.1-5+deb9u5_armel.deb 836e1d49074d542d20bd4e39a0ab92fa65ad881add176c7fa1db4655285aafa3 353366 libcurl4-openssl-dev_7.52.1-5+deb9u5_armel.deb Files: 6cb3e51059e450ea81c1315214bf13b7 128830 debug extra curl-dbgsym_7.52.1-5+deb9u5_armel.deb c0bdf39a2eda1abed5b14b8565a5a579 10318 web optional curl_7.52.1-5+deb9u5_armel.buildinfo e4f1380b14673f0192cd90835cdd7953 223534 web optional curl_7.52.1-5+deb9u5_armel.deb 9d480eeba0d08c86f77eb52b30e090ec 4936140 debug extra libcurl3-dbg_7.52.1-5+deb9u5_armel.deb 63fb5066beba08ce932234c3badcfd7c 259722 libs optional libcurl3-gnutls_7.52.1-5+deb9u5_armel.deb 49a274d48354c583afb3ffeafd58877b 264830 libs optional libcurl3-nss_7.52.1-5+deb9u5_armel.deb 7336d9589aa9187ab6a1d3a50135a5a1 260856 libs optional libcurl3_7.52.1-5+deb9u5_armel.deb 5ad85f592d5a761f3577c5900d2e12c2 351774 libdevel optional libcurl4-gnutls-dev_7.52.1-5+deb9u5_armel.deb a79c2e136d9d5c56ce7edede1af6a365 357594 libdevel optional libcurl4-nss-dev_7.52.1-5+deb9u5_armel.deb 812b9b47bab6daa6e00df8a25f93bc98 353366 libdevel optional libcurl4-openssl-dev_7.52.1-5+deb9u5_armel.deb -----BEGIN PGP SIGNATURE----- iQIzBAEBCgAdFiEEs35Pb15w9UmrHo0iDTh4hYjO57MFAlqoctsACgkQDTh4hYjO 57N5uA//fSX8tKQ8yjhYsHFSUDzcGmw9OEnMxOahhaC+fMd9dhwhguCj641GXxyY qWF2EuYa88E6ELccRrtHQvm/xyLS2aXsLPkJnhR83vBKY7S+xJ1h8AeLzqijR3Sc E0cLnWBvTw8Q4m0TVfbRgmNNLVekRxS4iIBpWc0qj5GH6xbbCRY0/3LaNaXQWGtM HTXIwliO6QaJlATgAPMgPZ/Y0DdAMhZT69zlpJikAY0IO5nDrpojVNQkp5y+E4kb NINCvbcw2T49nMiTJqGZ2bOsHNH0hdaw0ygpsvCWX97jNAQn8aacguYkh7EwbcoX RQLfXOdx6tC9yawJsZISd7p6mahcraWkmEqdUV9dIvF4jdyFeLQ5m2zQpOIkOUuB 7C12UcDon/xSP+aPucJXeqqmgJBvqx+x2BE1umSF27CeaoWhpNAgJlK0+NPN868P K9UooY4GNm5QYf4nffpQ0hV0XdmmZgIRpCi/W6elxKk6YRN5OjoOcGu/NwUizTJ9 A6Uxie+qnuSIjKnkH7MNXvwA5HfaDgnDWTsdKUgpJpN64WkBwEOsE8JgDA1RMK0l k9PJOBYY6qO05SF5foPhzS5QpOCwVaOANX9yYZaXBYXA0m/XvZb8+FUDAPvlFLVY ZiHOdJgtcCo9VRGTv6VGfaA74PSAOqRPGaNFaJA4xaOLLXJX9KA= =g0DG -----END PGP SIGNATURE-----