Format: 1.8 Date: Fri, 05 Aug 2016 11:17:47 -0400 Source: curl Binary: curl libcurl3 libcurl3-gnutls libcurl3-nss libcurl4-openssl-dev libcurl4-gnutls-dev libcurl4-nss-dev libcurl3-dbg libcurl4-doc Architecture: s390x Version: 7.47.0-1ubuntu2.1 Distribution: xenial Urgency: medium Maintainer: Launchpad Build Daemon Changed-By: Marc Deslauriers Description: curl - command line tool for transferring data with URL syntax libcurl3 - easy-to-use client-side URL transfer library (OpenSSL flavour) libcurl3-dbg - debugging symbols for libcurl (OpenSSL, GnuTLS and NSS flavours) libcurl3-gnutls - easy-to-use client-side URL transfer library (GnuTLS flavour) libcurl3-nss - easy-to-use client-side URL transfer library (NSS flavour) libcurl4-doc - documentation for libcurl libcurl4-gnutls-dev - development files and documentation for libcurl (GnuTLS flavour) libcurl4-nss-dev - development files and documentation for libcurl (NSS flavour) libcurl4-openssl-dev - development files and documentation for libcurl (OpenSSL flavour) Changes: curl (7.47.0-1ubuntu2.1) xenial-security; urgency=medium . * SECURITY UPDATE: TLS session resumption client cert bypass - debian/patches/CVE-2016-5419.patch: switch off SSL session id when client cert is used in lib/url.c, lib/urldata.h, lib/vtls/vtls.c. - CVE-2016-5419 * SECURITY UPDATE: re-using connections with wrong client cert - debian/patches/CVE-2016-5420.patch: only reuse connections with the same client cert in lib/vtls/vtls.c. - CVE-2016-5420 * SECURITY UPDATE: use of connection struct after free - debian/patches/CVE-2016-5421.patch: clear connection pointer for easy handles in lib/multi.c. - CVE-2016-5421 Checksums-Sha1: f4671a361f0a28b21015df7b89b561fcc8bc4f34 1086 curl-dbgsym_7.47.0-1ubuntu2.1_s390x.ddeb 8ee0f295940709caf7027e0af7acbfc81bb1d2f0 136730 curl_7.47.0-1ubuntu2.1_s390x.deb c424becd63cdb058e53719d1e5848da636109f44 3593864 libcurl3-dbg_7.47.0-1ubuntu2.1_s390x.deb d3ad1d105556322166690204fff52759af7cfb1b 1202 libcurl3-dbgsym_7.47.0-1ubuntu2.1_s390x.ddeb 05e545f98e565023cff935155c35b266a5d8bd91 1210 libcurl3-gnutls-dbgsym_7.47.0-1ubuntu2.1_s390x.ddeb 9ba7029c9fdb3e9db896e0b4392088ab1b70c90d 172646 libcurl3-gnutls_7.47.0-1ubuntu2.1_s390x.deb 20590a5ff8afc2ba3b3273aa552b437ec491a6e5 1206 libcurl3-nss-dbgsym_7.47.0-1ubuntu2.1_s390x.ddeb 7632df34ec247fbcdd1f8673198f548a05c33181 179558 libcurl3-nss_7.47.0-1ubuntu2.1_s390x.deb 7930bd2e260de7d53696d3e3f9cd357e0ac07e3d 175216 libcurl3_7.47.0-1ubuntu2.1_s390x.deb 9bec0f93c901f5722235073b28a75757845ba9a9 1292 libcurl4-gnutls-dev-dbgsym_7.47.0-1ubuntu2.1_s390x.ddeb 828e52516220e3068d9867d319b35d27e162f0d8 253044 libcurl4-gnutls-dev_7.47.0-1ubuntu2.1_s390x.deb bd59d5e716e3a4daab5a5bf40f97f00b062b89d7 1288 libcurl4-nss-dev-dbgsym_7.47.0-1ubuntu2.1_s390x.ddeb e9c158fc818d5c9d9aaa600d73f874b6b9c1448c 259584 libcurl4-nss-dev_7.47.0-1ubuntu2.1_s390x.deb 9a4824e0b9bfffcd5dc9dd7bb8cfe4c77dcbb92c 1290 libcurl4-openssl-dev-dbgsym_7.47.0-1ubuntu2.1_s390x.ddeb ec03796d780bda0fe024e8c6733be2e230df08d1 254568 libcurl4-openssl-dev_7.47.0-1ubuntu2.1_s390x.deb Checksums-Sha256: c54e11fecc1b6541af1ad38d03412d2b4572684d60dbeccec2883d3ec31b4109 1086 curl-dbgsym_7.47.0-1ubuntu2.1_s390x.ddeb 5aa1d0fee0c13ba188c64f3e9b38e77b20cb01046eec4e5857211b9f18b9c8c3 136730 curl_7.47.0-1ubuntu2.1_s390x.deb 9cf4a57fe13f887edfff87dcf53369b83b5b8ff836db21ad2ad2fe2ab46e688a 3593864 libcurl3-dbg_7.47.0-1ubuntu2.1_s390x.deb a7faca203ceafb5d999943da03ac5dfc0366c7978068810f0847dab399879dc4 1202 libcurl3-dbgsym_7.47.0-1ubuntu2.1_s390x.ddeb 4b7168f4e07bf16ec092fd59413727a261661d363a69ef54d233559280aa4e66 1210 libcurl3-gnutls-dbgsym_7.47.0-1ubuntu2.1_s390x.ddeb 6dacd42a411699ccf591686ba082870db0c220a5227719373187a0c40c177b84 172646 libcurl3-gnutls_7.47.0-1ubuntu2.1_s390x.deb c4783963de0015d79dab3cc1845f7f8ee32ce399c8e3d2455330442ee939fb96 1206 libcurl3-nss-dbgsym_7.47.0-1ubuntu2.1_s390x.ddeb c525a95c63d17f7f46bf24e42f4addc95dfbe4e45803ba8fc9daec6b1a4eb204 179558 libcurl3-nss_7.47.0-1ubuntu2.1_s390x.deb 977b51932352863222fa4d3c734647d7e83653a18be8e87b5a2e7c55750d367f 175216 libcurl3_7.47.0-1ubuntu2.1_s390x.deb 9a43a7b027ff693f4567a6660deb917c2b07df4101cc91aab1e3af35cf883948 1292 libcurl4-gnutls-dev-dbgsym_7.47.0-1ubuntu2.1_s390x.ddeb 90f7beff9c0dc2a3e41ab1b0ff652d52a687bcb1b80ed1e6b517564577795ba5 253044 libcurl4-gnutls-dev_7.47.0-1ubuntu2.1_s390x.deb bf230996d0b043f506114f5f60d6fe91fa4079e41324cc041b5b1bc5453cc69e 1288 libcurl4-nss-dev-dbgsym_7.47.0-1ubuntu2.1_s390x.ddeb e05474027dd7086cfefb47328672e09b1e8db25697ffe2765bd7e3ff6aa72ad8 259584 libcurl4-nss-dev_7.47.0-1ubuntu2.1_s390x.deb 99f31693652d5cc4968dff742f0bf333054a8ce4279d795bbf74200a7bf12fb7 1290 libcurl4-openssl-dev-dbgsym_7.47.0-1ubuntu2.1_s390x.ddeb 57595bc34adc056a0ebbfa2542e471e26e15e94eb4f748ef67cdfa075cbf3ca0 254568 libcurl4-openssl-dev_7.47.0-1ubuntu2.1_s390x.deb Files: 6356b086000b17bad4869bce269b5fbe 1086 web extra curl-dbgsym_7.47.0-1ubuntu2.1_s390x.ddeb 40a5edbb4c1ee5b7fcadd41fe31d5649 136730 web optional curl_7.47.0-1ubuntu2.1_s390x.deb 141b1be57cb5a574979c546b39159b21 3593864 debug extra libcurl3-dbg_7.47.0-1ubuntu2.1_s390x.deb 5eb3c495f5a611b6860c306de708d0e1 1202 libs extra libcurl3-dbgsym_7.47.0-1ubuntu2.1_s390x.ddeb 6270bca8dea703ac9ff86ba1a61ade93 1210 libs extra libcurl3-gnutls-dbgsym_7.47.0-1ubuntu2.1_s390x.ddeb 016b72faf9a70fa778ed388d03477d35 172646 libs optional libcurl3-gnutls_7.47.0-1ubuntu2.1_s390x.deb e377bbd7a666d4c57746b152044b6cd8 1206 libs extra libcurl3-nss-dbgsym_7.47.0-1ubuntu2.1_s390x.ddeb be3bb13016550fcaf99b3b0facca830e 179558 libs optional libcurl3-nss_7.47.0-1ubuntu2.1_s390x.deb c3ce8d29b6cee72b45c67e23eaaf90e7 175216 libs optional libcurl3_7.47.0-1ubuntu2.1_s390x.deb 69413acc2c351135ae3399ca86c1feec 1292 libdevel extra libcurl4-gnutls-dev-dbgsym_7.47.0-1ubuntu2.1_s390x.ddeb 05a79c492d065f90df6d2f5f8d09a642 253044 libdevel optional libcurl4-gnutls-dev_7.47.0-1ubuntu2.1_s390x.deb 41d9177812b5db41c1208f46c9c3f4a7 1288 libdevel extra libcurl4-nss-dev-dbgsym_7.47.0-1ubuntu2.1_s390x.ddeb 413b420f7c60968720038faa6487df5a 259584 libdevel optional libcurl4-nss-dev_7.47.0-1ubuntu2.1_s390x.deb 6229e5a47398fcf4d9a330136dd48dcb 1290 libdevel extra libcurl4-openssl-dev-dbgsym_7.47.0-1ubuntu2.1_s390x.ddeb d1c50b507dc40668b19b3bd751e35186 254568 libdevel optional libcurl4-openssl-dev_7.47.0-1ubuntu2.1_s390x.deb Original-Maintainer: Alessandro Ghedini