Format: 1.8 Date: Mon, 29 Oct 2018 08:10:57 -0400 Source: curl Binary: curl libcurl4 libcurl3-gnutls libcurl3-nss libcurl4-openssl-dev libcurl4-gnutls-dev libcurl4-nss-dev libcurl4-doc Architecture: s390x Version: 7.58.0-2ubuntu3.5 Distribution: bionic Urgency: medium Maintainer: Launchpad Build Daemon Changed-By: Marc Deslauriers Description: curl - command line tool for transferring data with URL syntax libcurl3-gnutls - easy-to-use client-side URL transfer library (GnuTLS flavour) libcurl3-nss - easy-to-use client-side URL transfer library (NSS flavour) libcurl4 - easy-to-use client-side URL transfer library (OpenSSL flavour) libcurl4-doc - documentation for libcurl libcurl4-gnutls-dev - development files and documentation for libcurl (GnuTLS flavour) libcurl4-nss-dev - development files and documentation for libcurl (NSS flavour) libcurl4-openssl-dev - development files and documentation for libcurl (OpenSSL flavour) Changes: curl (7.58.0-2ubuntu3.5) bionic-security; urgency=medium . * SECURITY UPDATE: SASL password overflow via integer overflow - debian/patches/CVE-2018-16839-pre.patch: fix integer overflow check in lib/curl_ntlm_core.c, lib/curl_setup.h, lib/vauth/cleartext.c. - debian/patches/CVE-2018-16839.patch: fix check in lib/vauth/cleartext.c. - CVE-2018-16839 * SECURITY UPDATE: warning message out-of-buffer read - debian/patches/oob-read.patch: fix bad arithmetic in src/tool_msgs.c. - CVE number pending Checksums-Sha1: 256e91f243c005ec19d9e3b8311e8827adb84853 150284 curl-dbgsym_7.58.0-2ubuntu3.5_s390x.ddeb e2f7e05d90c36caaefb88e0b0a67f3489c860036 11157 curl_7.58.0-2ubuntu3.5_s390x.buildinfo 31e65d866a7daaa2e8711cb8c9d443a5d69833ff 155176 curl_7.58.0-2ubuntu3.5_s390x.deb f402362f339817fa631a4e9ab88bd1b72e95fc21 1353164 libcurl3-gnutls-dbgsym_7.58.0-2ubuntu3.5_s390x.ddeb 4360c357eec47b0af7cac1c80f21a81d101d89c7 194856 libcurl3-gnutls_7.58.0-2ubuntu3.5_s390x.deb 556dff978b25b53186af0b2a851ff2c4ceb96345 1385600 libcurl3-nss-dbgsym_7.58.0-2ubuntu3.5_s390x.ddeb 9c11b5814f3fea164502210c3f5994bdf6072a4f 201264 libcurl3-nss_7.58.0-2ubuntu3.5_s390x.deb e01fcffefa367f900eb5fabe84a7a4e9f80a80d7 1365140 libcurl4-dbgsym_7.58.0-2ubuntu3.5_s390x.ddeb 85506c525d7cbe2d4e10d106b31f9c568216d6a4 280464 libcurl4-gnutls-dev_7.58.0-2ubuntu3.5_s390x.deb b87eda0993a7d11bc5276adcb7ac6e5806206530 287048 libcurl4-nss-dev_7.58.0-2ubuntu3.5_s390x.deb b53a2eccc804796f9f805e49bcde327eab610af9 280608 libcurl4-openssl-dev_7.58.0-2ubuntu3.5_s390x.deb 0fea3abb7d7138c03b1d8923d6aa14008f4e26b4 196088 libcurl4_7.58.0-2ubuntu3.5_s390x.deb Checksums-Sha256: c9182989359b5a8d6136c9e8a1c1f227834611fc67de438db068109c6d4a706e 150284 curl-dbgsym_7.58.0-2ubuntu3.5_s390x.ddeb 904c4c311135a2b5729b0dabe7fef000ca30dfec96b00ccbc59f36e38ccdaf60 11157 curl_7.58.0-2ubuntu3.5_s390x.buildinfo 1a0939490ae49389304ba65863f86e43323154b02a1a6281d0506ef638bdca6e 155176 curl_7.58.0-2ubuntu3.5_s390x.deb f177abe1b3153c6dfd3d689769f739bc9cc8d22e858ea0e416318c31cb68e39d 1353164 libcurl3-gnutls-dbgsym_7.58.0-2ubuntu3.5_s390x.ddeb 0bc9353f5e976afc551d2422d2a90fd6e3309d7ba1740fda22dca9e59bf105d1 194856 libcurl3-gnutls_7.58.0-2ubuntu3.5_s390x.deb 881b9a43a3a26b9870f13bc7333b13b532396612d4d441b5087f22969ca8a203 1385600 libcurl3-nss-dbgsym_7.58.0-2ubuntu3.5_s390x.ddeb 26338aef864d76385c4506a1d6b189186057e51979664a323e0ac69621610678 201264 libcurl3-nss_7.58.0-2ubuntu3.5_s390x.deb 9c556ffa3eaa3ce174dd336fd3ced54113f33b5f739233d3b1b6eafc81705eb5 1365140 libcurl4-dbgsym_7.58.0-2ubuntu3.5_s390x.ddeb b4b5143c0ff77c44fca8814ab2d6dc5f05d02d93a27e2619d3f8c048f87e460d 280464 libcurl4-gnutls-dev_7.58.0-2ubuntu3.5_s390x.deb 36281e015aeb489815b21cb906079c38906dc44bcf52d8331b917932be1e9be6 287048 libcurl4-nss-dev_7.58.0-2ubuntu3.5_s390x.deb 7229b61a9bea16d468773ffc215a3e77a4be213e3cfe73b1a63c257b21707eed 280608 libcurl4-openssl-dev_7.58.0-2ubuntu3.5_s390x.deb 706f68fa505a35d3b40233ffde7c63aee400346d919ceb07e3389a4b0a22cf5d 196088 libcurl4_7.58.0-2ubuntu3.5_s390x.deb Files: 6ec078aa4fe96694069f7cdcc546f572 150284 debug optional curl-dbgsym_7.58.0-2ubuntu3.5_s390x.ddeb 361d1e34eddcc9e99cbfe2da8c63bdd6 11157 web optional curl_7.58.0-2ubuntu3.5_s390x.buildinfo 4928f3d3e14ee02a81355fae821a7347 155176 web optional curl_7.58.0-2ubuntu3.5_s390x.deb 1698e85f1a55b82d19b1e161fbb16ea0 1353164 debug optional libcurl3-gnutls-dbgsym_7.58.0-2ubuntu3.5_s390x.ddeb fbd206a5fd8581110802a12161744584 194856 libs optional libcurl3-gnutls_7.58.0-2ubuntu3.5_s390x.deb 4b3d3b8fa5ca7aa54d8a1b37c59811ab 1385600 debug optional libcurl3-nss-dbgsym_7.58.0-2ubuntu3.5_s390x.ddeb 8743d2b24eb0f02719e9817c76a0b422 201264 libs optional libcurl3-nss_7.58.0-2ubuntu3.5_s390x.deb 8b32093c40bcf11ed60acc3bb1aa1c51 1365140 debug optional libcurl4-dbgsym_7.58.0-2ubuntu3.5_s390x.ddeb b815ebb00c1eb34bce00d58212c09b4e 280464 libdevel optional libcurl4-gnutls-dev_7.58.0-2ubuntu3.5_s390x.deb ead04127e41b5a89cbbeb6cdc49a6160 287048 libdevel optional libcurl4-nss-dev_7.58.0-2ubuntu3.5_s390x.deb 618889fea36f896bcdee696bbf33f15f 280608 libdevel optional libcurl4-openssl-dev_7.58.0-2ubuntu3.5_s390x.deb c451f61069a826a17f2068f996c0bdec 196088 libs optional libcurl4_7.58.0-2ubuntu3.5_s390x.deb Original-Maintainer: Alessandro Ghedini