Format: 1.8 Date: Tue, 05 May 2015 14:17:51 -0400 Source: curl Binary: curl curl-udeb libcurl3 libcurl3-udeb libcurl3-gnutls libcurl3-nss libcurl4-openssl-dev libcurl4-gnutls-dev libcurl4-nss-dev libcurl3-dbg libcurl4-doc Architecture: i386 Version: 7.38.0-3ubuntu3 Distribution: wily-proposed Urgency: medium Maintainer: Ubuntu/amd64 Build Daemon Changed-By: Marc Deslauriers Description: curl - command line tool for transferring data with URL syntax curl-udeb - Get a file from an HTTP, HTTPS or FTP server (udeb) libcurl3 - easy-to-use client-side URL transfer library (OpenSSL flavour) libcurl3-dbg - debugging symbols for libcurl (OpenSSL, GnuTLS and NSS flavours) libcurl3-gnutls - easy-to-use client-side URL transfer library (GnuTLS flavour) libcurl3-nss - easy-to-use client-side URL transfer library (NSS flavour) libcurl3-udeb - Multi-protocol file transfer library (OpenSSL) (udeb) libcurl4-doc - documentation for libcurl libcurl4-gnutls-dev - development files and documentation for libcurl (GnuTLS flavour) libcurl4-nss-dev - development files and documentation for libcurl (NSS flavour) libcurl4-openssl-dev - development files and documentation for libcurl (OpenSSL flavour) Changes: curl (7.38.0-3ubuntu3) wily; urgency=medium . * SECURITY UPDATE: NTLM connection reuse when unauthenticated - debian/patches/CVE-2015-3143.patch: require credentials to match in lib/url.c. - CVE-2015-3143 * SECURITY UPDATE: host name out of boundary memory access - debian/patches/CVE-2015-3144.patch: check for valid length in lib/url.c. - CVE-2015-3144 * SECURITY UPDATE: cookie parser out of boundary memory access - debian/patches/CVE-2015-3145.patch: properly handle a single double quote in lib/cookie.c. - CVE-2015-3145 * SECURITY UPDATE: negotiate not treated as connection-oriented - debian/patches/CVE-2015-3148.patch: close Negotiate connections when done in lib/http.c. - CVE-2015-3148 * SECURITY UPDATE: sensitive HTTP server headers disclosure to proxies - debian/patches/CVE-2015-3153.patch: make HTTP headers separated in docs/libcurl/opts/CURLOPT_HEADEROPT.3, lib/url.c, tests/data/test1527, tests/data/test287, tests/libtest/lib1527.c. - CVE-2015-3153 Checksums-Sha1: 6b651818ae2e7cee1552ac82f92968e13694fc12 131360 curl_7.38.0-3ubuntu3_i386.deb 0812217052f5bb3279e61658d24b73e5708bf6af 1000 curl-udeb_7.38.0-3ubuntu3_i386.udeb 69d36384ea1c52501950755629ab13720dce3cca 198242 libcurl3_7.38.0-3ubuntu3_i386.deb 0179dd150f073ce2786cac7671f862c14249f6a3 884 libcurl3-udeb_7.38.0-3ubuntu3_i386.udeb 6076328c234df3893a250b767f6f68121c0fe21f 189350 libcurl3-gnutls_7.38.0-3ubuntu3_i386.deb 3ff957df9b45e55a1c14275ac10d7f951c01f188 200996 libcurl3-nss_7.38.0-3ubuntu3_i386.deb 8e29121a1535881736ce330feb13bbaf8ce0aa1a 276164 libcurl4-openssl-dev_7.38.0-3ubuntu3_i386.deb ca465e070c846c982a78776afe4d5c97b664a4a2 266350 libcurl4-gnutls-dev_7.38.0-3ubuntu3_i386.deb 59aae3d0ec3373d1c11b9b134da934e49920153a 279862 libcurl4-nss-dev_7.38.0-3ubuntu3_i386.deb 344e513c77cc1256f64d417391326ecdb47ac689 2873946 libcurl3-dbg_7.38.0-3ubuntu3_i386.deb 177c6eca0dce65b2aa456a2c6c65ced3ee5583a6 1136 curl-dbgsym_7.38.0-3ubuntu3_i386.ddeb 25197ddb91870b869cdf4d325605ea60878bc405 1038 curl-udeb-dbgsym_7.38.0-3ubuntu3_i386.ddeb ef87dd6855bac2c4f748b39aac450304d7301d83 1246 libcurl3-dbgsym_7.38.0-3ubuntu3_i386.ddeb a11033fe7fdf064e2f0b32a3745fc27f1d0060df 950 libcurl3-udeb-dbgsym_7.38.0-3ubuntu3_i386.ddeb 5309984fb850bfa9cd9973aae5e6ed99cb886ee4 1254 libcurl3-gnutls-dbgsym_7.38.0-3ubuntu3_i386.ddeb bbacf5824ae8653363d348506072c6f7e0844396 1250 libcurl3-nss-dbgsym_7.38.0-3ubuntu3_i386.ddeb 74fa570ac7adcdc1b6f574893b69125d5a098398 1336 libcurl4-openssl-dev-dbgsym_7.38.0-3ubuntu3_i386.ddeb 02e34a5ffd677472ad735251fb180f9efd9e4abb 1338 libcurl4-gnutls-dev-dbgsym_7.38.0-3ubuntu3_i386.ddeb 0aea2e082e54749e378e669d9225ff1babbdbc23 1336 libcurl4-nss-dev-dbgsym_7.38.0-3ubuntu3_i386.ddeb Checksums-Sha256: 74bdfbc98c8b996f6f09c452f2ea82bcc1a3ff83bdbf4c44341b7e0b9a0361de 131360 curl_7.38.0-3ubuntu3_i386.deb ea138da54ff9f38a6de6bbabcd4e4101871b4b62f77bf6b7a523d9736ecc036f 1000 curl-udeb_7.38.0-3ubuntu3_i386.udeb cd286c10eac45622cae1492a38ea0e5ff9e0bb1cf1a4084d2cd1577896ff721d 198242 libcurl3_7.38.0-3ubuntu3_i386.deb bfa327a14f2f1f40e70171cff5273d426f0cacf2d00ce5499f576c8a4915d302 884 libcurl3-udeb_7.38.0-3ubuntu3_i386.udeb 41c90355af54772e60d9aeaae9d06744cdc5e1593b2f4794306856548c7caba8 189350 libcurl3-gnutls_7.38.0-3ubuntu3_i386.deb 21d8d334d4061c72630cd799aedd760c1de0129cb8d30128a2794d97853e8934 200996 libcurl3-nss_7.38.0-3ubuntu3_i386.deb f94d12aea38d50b64f0c36bf84f150ef4c6f2b812a367c7b24e90df0cbc5b6e4 276164 libcurl4-openssl-dev_7.38.0-3ubuntu3_i386.deb 73630679a4a08f334a77f451e1b98c55e2bd024cb39e9129ee0872a7ef08ca73 266350 libcurl4-gnutls-dev_7.38.0-3ubuntu3_i386.deb 2af2471ba839313d86a8b3fead55a5e59f626f3a81976fab8daa659dda34adca 279862 libcurl4-nss-dev_7.38.0-3ubuntu3_i386.deb adc34594090a2b41fac1f9af8ba99d70c25160e71e47b7b0c942c3afd1566ff0 2873946 libcurl3-dbg_7.38.0-3ubuntu3_i386.deb d80c7ff8e274a6752b125d780451c5e7ef06e206b9af914a39c251d93b3716b4 1136 curl-dbgsym_7.38.0-3ubuntu3_i386.ddeb 651a019d803a6f94b41dee5ae9788c2e068257ba42274ccedac43f15f7f76e7e 1038 curl-udeb-dbgsym_7.38.0-3ubuntu3_i386.ddeb 9302bd733da7ab9d02cd21eb628b40c6d0a65129fe4c6f3f1601697a1ba94688 1246 libcurl3-dbgsym_7.38.0-3ubuntu3_i386.ddeb 23711b6c9ef2a09285f82dbdfa8f47e3662932fea31ceb258d942a1bd6650a6a 950 libcurl3-udeb-dbgsym_7.38.0-3ubuntu3_i386.ddeb 7b1580f61dd3927ed37080dc36bf0b9970f9f5c2dc045733b978fef17876e2da 1254 libcurl3-gnutls-dbgsym_7.38.0-3ubuntu3_i386.ddeb 4e22b3fbbbb2ba9b0db19f53e2b7876f4830977ab0887c56fd0b9ac7f689f548 1250 libcurl3-nss-dbgsym_7.38.0-3ubuntu3_i386.ddeb 5af13e94abc4c56d1f54a3021bca555a6a1fc8afc2671e8df958d44f2a0ccd15 1336 libcurl4-openssl-dev-dbgsym_7.38.0-3ubuntu3_i386.ddeb bf9a32864e91c3960766f8f264a87d9fb69f4d009d83e3d89717bfbadc4db482 1338 libcurl4-gnutls-dev-dbgsym_7.38.0-3ubuntu3_i386.ddeb 34287b84887f5532f82d48c8c1c5fff3d8b2af0894c73ec5fdce33dd811d45df 1336 libcurl4-nss-dev-dbgsym_7.38.0-3ubuntu3_i386.ddeb Files: 6f7d12c3a9c4942f57c43707f911af82 131360 web optional curl_7.38.0-3ubuntu3_i386.deb 40247e97083d7232f399c3ba9c54ad4f 1000 debian-installer optional curl-udeb_7.38.0-3ubuntu3_i386.udeb b8b4e4d01d05ebbc61a5215ed042e3c3 198242 libs optional libcurl3_7.38.0-3ubuntu3_i386.deb 656e048012bab5b752304252380275bd 884 debian-installer optional libcurl3-udeb_7.38.0-3ubuntu3_i386.udeb 355457402ccc649343d309464654fd29 189350 libs optional libcurl3-gnutls_7.38.0-3ubuntu3_i386.deb 2097214669036fda763065d94df418c1 200996 libs optional libcurl3-nss_7.38.0-3ubuntu3_i386.deb 6d3896aa03ac105a22cb3028fd52ac42 276164 libdevel optional libcurl4-openssl-dev_7.38.0-3ubuntu3_i386.deb 38bd057c002511c488f9e8d339a0e920 266350 libdevel optional libcurl4-gnutls-dev_7.38.0-3ubuntu3_i386.deb 5cc7c6dab784a942034934d4218416f2 279862 libdevel optional libcurl4-nss-dev_7.38.0-3ubuntu3_i386.deb 4ea07535dc4f5af49db82473c42eaf67 2873946 debug extra libcurl3-dbg_7.38.0-3ubuntu3_i386.deb 04eedcd6fa2a93ac472f4aa2a2478401 1136 web extra curl-dbgsym_7.38.0-3ubuntu3_i386.ddeb eea375c03dea43a04662f69e8e632c11 1038 debian-installer extra curl-udeb-dbgsym_7.38.0-3ubuntu3_i386.ddeb 79dd294b1f2800cab3de1b92a250a5e8 1246 libs extra libcurl3-dbgsym_7.38.0-3ubuntu3_i386.ddeb 76ae9167bda189cc068432ab026286f7 950 debian-installer extra libcurl3-udeb-dbgsym_7.38.0-3ubuntu3_i386.ddeb 64c510383d1a133df942b1de10be3042 1254 libs extra libcurl3-gnutls-dbgsym_7.38.0-3ubuntu3_i386.ddeb 669a227a4f35a87f8a9aaac4a440062d 1250 libs extra libcurl3-nss-dbgsym_7.38.0-3ubuntu3_i386.ddeb 308a582d1577299ea01e8288ca2b7b34 1336 libdevel extra libcurl4-openssl-dev-dbgsym_7.38.0-3ubuntu3_i386.ddeb 64acfe16940d7d432b599b3afd67a4f5 1338 libdevel extra libcurl4-gnutls-dev-dbgsym_7.38.0-3ubuntu3_i386.ddeb 3faaf8076033efb90e6615e96e8a85dd 1336 libdevel extra libcurl4-nss-dev-dbgsym_7.38.0-3ubuntu3_i386.ddeb Original-Maintainer: Alessandro Ghedini Package-Type: udeb