Format: 1.8 Date: Thu, 15 Mar 2018 08:20:41 -0400 Source: curl Binary: curl libcurl4 libcurl3-gnutls libcurl3-nss libcurl4-openssl-dev libcurl4-gnutls-dev libcurl4-nss-dev libcurl4-doc Architecture: s390x Version: 7.58.0-2ubuntu3 Distribution: bionic-proposed Urgency: medium Maintainer: Launchpad Build Daemon Changed-By: Marc Deslauriers Description: curl - command line tool for transferring data with URL syntax libcurl3-gnutls - easy-to-use client-side URL transfer library (GnuTLS flavour) libcurl3-nss - easy-to-use client-side URL transfer library (NSS flavour) libcurl4 - easy-to-use client-side URL transfer library (OpenSSL flavour) libcurl4-doc - documentation for libcurl libcurl4-gnutls-dev - development files and documentation for libcurl (GnuTLS flavour) libcurl4-nss-dev - development files and documentation for libcurl (NSS flavour) libcurl4-openssl-dev - development files and documentation for libcurl (OpenSSL flavour) Changes: curl (7.58.0-2ubuntu3) bionic; urgency=medium . * SECURITY UPDATE: FTP path trickery leads to NIL byte OOB write - debian/patches/CVE-2018-1000120.patch: reject path components with control codes in lib/ftp.c, add test to tests/*. - CVE-2018-1000120 * SECURITY UPDATE: LDAP NULL pointer dereference - debian/patches/CVE-2018-1000121.patch: check ldap_get_attribute_ber() results for NULL before using in lib/openldap.c. - CVE-2018-1000121 * SECURITY UPDATE: RTSP RTP buffer over-read - debian/patches/CVE-2018-1000122.patch: make sure excess reads don't go beyond buffer end in lib/transfer.c. - CVE-2018-1000122 Checksums-Sha1: 2b673920e49535caf8ab3baeb796becbea732918 150256 curl-dbgsym_7.58.0-2ubuntu3_s390x.ddeb fbe23b1f46edc30a8f0bf75f40c057b8209d8b62 11019 curl_7.58.0-2ubuntu3_s390x.buildinfo 13734b4673c1d27e53325823538ee485e65eb20d 155144 curl_7.58.0-2ubuntu3_s390x.deb f5458ce9eb32e4334b80962c294be16724ca797c 1353088 libcurl3-gnutls-dbgsym_7.58.0-2ubuntu3_s390x.ddeb 7920ab26017e657100c2580a8c12d0bc4dc957f8 194924 libcurl3-gnutls_7.58.0-2ubuntu3_s390x.deb 22c0152396aefefe3d4e024b92f394bc69dc1693 1385928 libcurl3-nss-dbgsym_7.58.0-2ubuntu3_s390x.ddeb 22ef2d7cd546a7aad74a70cb251c7fec95c07c02 201396 libcurl3-nss_7.58.0-2ubuntu3_s390x.deb 69154a6b56fe5503e71c2d1ecfcd26453bf3495e 1365288 libcurl4-dbgsym_7.58.0-2ubuntu3_s390x.ddeb 4beec1f161de7c6929ce841b4d18f3cc71bed366 280316 libcurl4-gnutls-dev_7.58.0-2ubuntu3_s390x.deb ef49b63494774ea90a254b8fff619e8bf1980e71 286724 libcurl4-nss-dev_7.58.0-2ubuntu3_s390x.deb fc972c04ec2de705ac5f2d083faf50fce831b9d0 280988 libcurl4-openssl-dev_7.58.0-2ubuntu3_s390x.deb c83618f63b341c2b638db914b23bb99594bdfd96 196112 libcurl4_7.58.0-2ubuntu3_s390x.deb Checksums-Sha256: 562d83373723bc3f816b52a2e97b4d18ef3199fb6ed371c4409f8b2256eed763 150256 curl-dbgsym_7.58.0-2ubuntu3_s390x.ddeb 1361be777f0a87b1434dc1eba55246f02ea02daa83cd62af365e480bbb9dfa51 11019 curl_7.58.0-2ubuntu3_s390x.buildinfo 731d1db68a0870e9eb44f8e9365614e47201c98f3cc96762162672499b8a376f 155144 curl_7.58.0-2ubuntu3_s390x.deb 45c18a3c4e52d4d6db96806e1bdd5d3e44108cf7d79de7c8fd55f4c57570de6d 1353088 libcurl3-gnutls-dbgsym_7.58.0-2ubuntu3_s390x.ddeb c3237dcc947e99b1bce55378d9fe7289fd784a4b43b85b186368a97af01fdf99 194924 libcurl3-gnutls_7.58.0-2ubuntu3_s390x.deb fc0889e4c15541e513c005ab692832deabdaf95f733de3cd55f530902ec24af6 1385928 libcurl3-nss-dbgsym_7.58.0-2ubuntu3_s390x.ddeb 5eb0620ba4339ca3f96ef95f6b9e71344bb6003ec4702dc466b434e43d3b238e 201396 libcurl3-nss_7.58.0-2ubuntu3_s390x.deb 4d4776bdd37fc15434d43c9cf0698d2560f910ba6554bf2ddcd81f15f69cf62e 1365288 libcurl4-dbgsym_7.58.0-2ubuntu3_s390x.ddeb 2a33613fd86c2d52588f8e445301703447b28072d96f636a4c5c25b33e543ef6 280316 libcurl4-gnutls-dev_7.58.0-2ubuntu3_s390x.deb 86f1ba3a076b040a2eb6bcd002ecd3f36cd7b6323ac4c164dc4a5c9451676578 286724 libcurl4-nss-dev_7.58.0-2ubuntu3_s390x.deb 3c57b776982d007151ef0578dd33bf69e140e37cef425dce44d32b87175b9b3b 280988 libcurl4-openssl-dev_7.58.0-2ubuntu3_s390x.deb f7318cf85f0d9b9fa77a3d1645aa1882e2074ac9b3a49892c01353af881b96c6 196112 libcurl4_7.58.0-2ubuntu3_s390x.deb Files: d32a96e1d6158e7e717ce54498b3213a 150256 debug optional curl-dbgsym_7.58.0-2ubuntu3_s390x.ddeb 592434817621b4a76448eb6ea0c25556 11019 web optional curl_7.58.0-2ubuntu3_s390x.buildinfo e8414483a75f6f15db4d5ac4e634afb6 155144 web optional curl_7.58.0-2ubuntu3_s390x.deb 47934eb47ecaf8866c55f0f40c11cf54 1353088 debug optional libcurl3-gnutls-dbgsym_7.58.0-2ubuntu3_s390x.ddeb 4cdaa6bd17d6931aed3493d8c6904263 194924 libs optional libcurl3-gnutls_7.58.0-2ubuntu3_s390x.deb 2f893d12dca728649b16464c246f74ba 1385928 debug optional libcurl3-nss-dbgsym_7.58.0-2ubuntu3_s390x.ddeb d680d9a36d0d60fdd017a64665a3de4a 201396 libs optional libcurl3-nss_7.58.0-2ubuntu3_s390x.deb 68408139e4c08ee2349eafe6f596ff31 1365288 debug optional libcurl4-dbgsym_7.58.0-2ubuntu3_s390x.ddeb bbf85113a7fbcbc8e43389d9083bf7b0 280316 libdevel optional libcurl4-gnutls-dev_7.58.0-2ubuntu3_s390x.deb d141b5fe05d85519d0b947fceaf0ff02 286724 libdevel optional libcurl4-nss-dev_7.58.0-2ubuntu3_s390x.deb c972d5b47f417b7fc83890358d198502 280988 libdevel optional libcurl4-openssl-dev_7.58.0-2ubuntu3_s390x.deb b700a7314091daa0acfe731ef2ff75d4 196112 libs optional libcurl4_7.58.0-2ubuntu3_s390x.deb Original-Maintainer: Alessandro Ghedini