Format: 1.8 Date: Fri, 05 Aug 2016 11:17:47 -0400 Source: curl Binary: curl libcurl3 libcurl3-gnutls libcurl3-nss libcurl4-openssl-dev libcurl4-gnutls-dev libcurl4-nss-dev libcurl3-dbg libcurl4-doc Architecture: ppc64el Version: 7.47.0-1ubuntu2.1 Distribution: xenial Urgency: medium Maintainer: Launchpad Build Daemon Changed-By: Marc Deslauriers Description: curl - command line tool for transferring data with URL syntax libcurl3 - easy-to-use client-side URL transfer library (OpenSSL flavour) libcurl3-dbg - debugging symbols for libcurl (OpenSSL, GnuTLS and NSS flavours) libcurl3-gnutls - easy-to-use client-side URL transfer library (GnuTLS flavour) libcurl3-nss - easy-to-use client-side URL transfer library (NSS flavour) libcurl4-doc - documentation for libcurl libcurl4-gnutls-dev - development files and documentation for libcurl (GnuTLS flavour) libcurl4-nss-dev - development files and documentation for libcurl (NSS flavour) libcurl4-openssl-dev - development files and documentation for libcurl (OpenSSL flavour) Changes: curl (7.47.0-1ubuntu2.1) xenial-security; urgency=medium . * SECURITY UPDATE: TLS session resumption client cert bypass - debian/patches/CVE-2016-5419.patch: switch off SSL session id when client cert is used in lib/url.c, lib/urldata.h, lib/vtls/vtls.c. - CVE-2016-5419 * SECURITY UPDATE: re-using connections with wrong client cert - debian/patches/CVE-2016-5420.patch: only reuse connections with the same client cert in lib/vtls/vtls.c. - CVE-2016-5420 * SECURITY UPDATE: use of connection struct after free - debian/patches/CVE-2016-5421.patch: clear connection pointer for easy handles in lib/multi.c. - CVE-2016-5421 Checksums-Sha1: 389757b6b813ec6786846bf6a4ef196b191efe64 1090 curl-dbgsym_7.47.0-1ubuntu2.1_ppc64el.ddeb ed6b3834a390e8e5dbd6cb91931c480af1573fb4 136122 curl_7.47.0-1ubuntu2.1_ppc64el.deb 4e05b09bb97bc1247e5252c5707cbda5f332196a 3684214 libcurl3-dbg_7.47.0-1ubuntu2.1_ppc64el.deb ee52aacb83ed75f5c480cf6c37e4288d824b0f47 1206 libcurl3-dbgsym_7.47.0-1ubuntu2.1_ppc64el.ddeb 3f234b752a020c480e01982169c2d356765e1352 1210 libcurl3-gnutls-dbgsym_7.47.0-1ubuntu2.1_ppc64el.ddeb 0a2207bb067cbc601bdc5dcb41a11c7156214ded 176000 libcurl3-gnutls_7.47.0-1ubuntu2.1_ppc64el.deb 953717563b084fbd69f5cc86cba5f8c7b86bd513 1208 libcurl3-nss-dbgsym_7.47.0-1ubuntu2.1_ppc64el.ddeb 8dd48275503b7fd69ea97b7c03bcb7f111635057 181362 libcurl3-nss_7.47.0-1ubuntu2.1_ppc64el.deb 4a00339b9790729981efa94ef3eba4f92a80974a 176320 libcurl3_7.47.0-1ubuntu2.1_ppc64el.deb 5b14ac08019e15920eb91f62f24e7d010034de8c 1296 libcurl4-gnutls-dev-dbgsym_7.47.0-1ubuntu2.1_ppc64el.ddeb 4ba2e744054f1f7d6152c699ad5c58a58b26ee04 262106 libcurl4-gnutls-dev_7.47.0-1ubuntu2.1_ppc64el.deb 82248ea0da4aa5102dfb52a395236d6184ef899a 1290 libcurl4-nss-dev-dbgsym_7.47.0-1ubuntu2.1_ppc64el.ddeb 22e6522a42ffdead91f87d4c604e42a63272a73d 268350 libcurl4-nss-dev_7.47.0-1ubuntu2.1_ppc64el.deb 86575bf08986da0570da694e3af628c847dd9c05 1294 libcurl4-openssl-dev-dbgsym_7.47.0-1ubuntu2.1_ppc64el.ddeb 392cd2edc2fbde7328812c8ce4cc2b018629ae5c 260712 libcurl4-openssl-dev_7.47.0-1ubuntu2.1_ppc64el.deb Checksums-Sha256: 763f20d5da02e7a05ea389c60b5bc00329f88e5733e8dcbfc6d03586960a5b3a 1090 curl-dbgsym_7.47.0-1ubuntu2.1_ppc64el.ddeb 8b5e4a77cc4f6e5db864c184b1169e496e5e394a11c8127df8233d47e2f17de0 136122 curl_7.47.0-1ubuntu2.1_ppc64el.deb b42a581cdaf456e1e2f818b2e68a634843cde9f2ab2b13705f658457b9531f33 3684214 libcurl3-dbg_7.47.0-1ubuntu2.1_ppc64el.deb 4a58ab3227646f82b3c7ef0a5318550e5d492af303ec217f7b06aaece1669d3e 1206 libcurl3-dbgsym_7.47.0-1ubuntu2.1_ppc64el.ddeb b3f95e6ca07ece98bdea0c7a28391e611904fec1e0444bd3e539ebdc576efe12 1210 libcurl3-gnutls-dbgsym_7.47.0-1ubuntu2.1_ppc64el.ddeb 2981cbdc7da343c13603730aaf5cc5fd10ed21e4cd242ac00a1ff9a3bcd1966f 176000 libcurl3-gnutls_7.47.0-1ubuntu2.1_ppc64el.deb 6dabd4a19261df4e2e7f167112035693332ef29f6499520cf5ea0bbf9db8d66e 1208 libcurl3-nss-dbgsym_7.47.0-1ubuntu2.1_ppc64el.ddeb 215944f8b94e51547401abd3ca0b6dc60452f15eaf01ea7178cbe5aa4750ca87 181362 libcurl3-nss_7.47.0-1ubuntu2.1_ppc64el.deb 9022f05385bdced27880062c86782daa334936a43291bdee07f000deb5638dfa 176320 libcurl3_7.47.0-1ubuntu2.1_ppc64el.deb aa8ec922d4831b1f979497ac3e97727bcda3c40302f59d811be164d7f0326911 1296 libcurl4-gnutls-dev-dbgsym_7.47.0-1ubuntu2.1_ppc64el.ddeb 82a262f81f25a0eae6251c812697946c31bd0473858f6ff12803124156d91802 262106 libcurl4-gnutls-dev_7.47.0-1ubuntu2.1_ppc64el.deb b831977a07e4286177e1a3ad65620a373262637c65ac77ce2f181482564caba2 1290 libcurl4-nss-dev-dbgsym_7.47.0-1ubuntu2.1_ppc64el.ddeb f5a5cad05eb5baa39ce09879d392b84c78aa1d1f6cede329675e2e29eae2372d 268350 libcurl4-nss-dev_7.47.0-1ubuntu2.1_ppc64el.deb 19fe06b1261e5fb92959fe475874126122b270a1be3ef6480355842ad5e89bb0 1294 libcurl4-openssl-dev-dbgsym_7.47.0-1ubuntu2.1_ppc64el.ddeb 654d67f69fb9fd5ade458cad772178247783979f7bfd803e1e989857e5a975e4 260712 libcurl4-openssl-dev_7.47.0-1ubuntu2.1_ppc64el.deb Files: ea5b50a72e098c1eb6faa2b35fec2588 1090 web extra curl-dbgsym_7.47.0-1ubuntu2.1_ppc64el.ddeb fbf300a2b9ffaaa175ffa869d6973a3b 136122 web optional curl_7.47.0-1ubuntu2.1_ppc64el.deb 1223f043bc3c873fcddd77a359a871f6 3684214 debug extra libcurl3-dbg_7.47.0-1ubuntu2.1_ppc64el.deb 372e69b38b28b9cda5e32aacf81ee449 1206 libs extra libcurl3-dbgsym_7.47.0-1ubuntu2.1_ppc64el.ddeb e8a8fae117d1649b3f51af2823367f0a 1210 libs extra libcurl3-gnutls-dbgsym_7.47.0-1ubuntu2.1_ppc64el.ddeb ad2af8c37ac61d02d4a1cd1a3571e683 176000 libs optional libcurl3-gnutls_7.47.0-1ubuntu2.1_ppc64el.deb 102e3f92a5aabb08a2e6f647a0230edc 1208 libs extra libcurl3-nss-dbgsym_7.47.0-1ubuntu2.1_ppc64el.ddeb 7957cddf16c73c8186edf6309cd5fd3a 181362 libs optional libcurl3-nss_7.47.0-1ubuntu2.1_ppc64el.deb 3779453a5be0dc6184c738d460145315 176320 libs optional libcurl3_7.47.0-1ubuntu2.1_ppc64el.deb 2f06ae410d2f7196688b4b9f0d71e1f3 1296 libdevel extra libcurl4-gnutls-dev-dbgsym_7.47.0-1ubuntu2.1_ppc64el.ddeb ef413dfab713980919b60e59d3f24241 262106 libdevel optional libcurl4-gnutls-dev_7.47.0-1ubuntu2.1_ppc64el.deb 6bc8cc1558b0ebf052a1fc4b54a4466b 1290 libdevel extra libcurl4-nss-dev-dbgsym_7.47.0-1ubuntu2.1_ppc64el.ddeb b5aafc31081dba3a7aebb2e966087a2b 268350 libdevel optional libcurl4-nss-dev_7.47.0-1ubuntu2.1_ppc64el.deb 176a3e7145595e24bbb689932d36ffdc 1294 libdevel extra libcurl4-openssl-dev-dbgsym_7.47.0-1ubuntu2.1_ppc64el.ddeb d34faa9391e70e401a4bd3767f1fec18 260712 libdevel optional libcurl4-openssl-dev_7.47.0-1ubuntu2.1_ppc64el.deb Original-Maintainer: Alessandro Ghedini