Format: 1.8 Date: Tue, 23 Mar 2021 09:16:53 -0400 Source: curl Binary: curl libcurl3 libcurl3-gnutls libcurl3-nss libcurl4-openssl-dev libcurl4-gnutls-dev libcurl4-nss-dev libcurl3-dbg libcurl4-doc Architecture: s390x Version: 7.47.0-1ubuntu2.19 Distribution: xenial Urgency: medium Maintainer: Launchpad Build Daemon Changed-By: Marc Deslauriers Description: curl - command line tool for transferring data with URL syntax libcurl3 - easy-to-use client-side URL transfer library (OpenSSL flavour) libcurl3-dbg - debugging symbols for libcurl (OpenSSL, GnuTLS and NSS flavours) libcurl3-gnutls - easy-to-use client-side URL transfer library (GnuTLS flavour) libcurl3-nss - easy-to-use client-side URL transfer library (NSS flavour) libcurl4-doc - documentation for libcurl libcurl4-gnutls-dev - development files and documentation for libcurl (GnuTLS flavour) libcurl4-nss-dev - development files and documentation for libcurl (NSS flavour) libcurl4-openssl-dev - development files and documentation for libcurl (OpenSSL flavour) Changes: curl (7.47.0-1ubuntu2.19) xenial-security; urgency=medium . * SECURITY UPDATE: data leak via referer header field - debian/patches/urlapi.patch: backport url api support in include/curl/Makefile.am, include/curl/curl.h, include/curl/urlapi.h, lib/Makefile.inc, lib/urlapi-int.h, lib/urlapi.c, lib/curl_setup_once.h, lib/url.c, lib/url.h, lib/escape.c, lib/escape.h, docs/libcurl/symbols-in-versions. - debian/libcurl*.symbols: added new symbols. - debian/patches/CVE-2021-22876.patch: strip credentials from the auto-referer header field in lib/transfer.c. - CVE-2021-22876 Checksums-Sha1: a2f4a5da7aaeb60977701bbdd4f04ebd9cc4fccf 1086 curl-dbgsym_7.47.0-1ubuntu2.19_s390x.ddeb 9a8d61eb3168f53410e393ede672044603079904 136934 curl_7.47.0-1ubuntu2.19_s390x.deb 4a8d30c7bbc4a0406242a6f2e88e8806eb140ef4 3686418 libcurl3-dbg_7.47.0-1ubuntu2.19_s390x.deb 4375bba771a840b0efef4fd6c118c117a6bd2fa2 1204 libcurl3-dbgsym_7.47.0-1ubuntu2.19_s390x.ddeb 800b0af1206872a4a15d9a6fe16dec4bd787347b 1212 libcurl3-gnutls-dbgsym_7.47.0-1ubuntu2.19_s390x.ddeb 341ffc244d08a41764e3899718e194ab1894495e 178744 libcurl3-gnutls_7.47.0-1ubuntu2.19_s390x.deb 7b59f86f57f80d36c25fd332fbfe2e664dc3c8a3 1208 libcurl3-nss-dbgsym_7.47.0-1ubuntu2.19_s390x.ddeb b22942f0ccc5de7c1440d9a33591b748d2fb39cd 184836 libcurl3-nss_7.47.0-1ubuntu2.19_s390x.deb d5b9b2a7cd9e72d810f7f6e070234596a62d29fb 180610 libcurl3_7.47.0-1ubuntu2.19_s390x.deb 2bc7f45b184f825af1fd3ef417a0c0fa1fa4aece 1294 libcurl4-gnutls-dev-dbgsym_7.47.0-1ubuntu2.19_s390x.ddeb 4936d66cc6cbecc3690004040915c421addd9715 259798 libcurl4-gnutls-dev_7.47.0-1ubuntu2.19_s390x.deb 1747c3329d6e8e5a1821b9104e7e457da430de34 1290 libcurl4-nss-dev-dbgsym_7.47.0-1ubuntu2.19_s390x.ddeb 3a41a13900cc760ff032ce3d0162ae666f1e2b58 267070 libcurl4-nss-dev_7.47.0-1ubuntu2.19_s390x.deb 300a981f73afad0c9515bb416fe445e8a9975904 1292 libcurl4-openssl-dev-dbgsym_7.47.0-1ubuntu2.19_s390x.ddeb a836a4363663df24481a61bd8a9b7129980e13f0 261630 libcurl4-openssl-dev_7.47.0-1ubuntu2.19_s390x.deb Checksums-Sha256: e483710b5cef0c4e63f108a589b5f509d5920c54e7e08797ab364842ecf5f3d3 1086 curl-dbgsym_7.47.0-1ubuntu2.19_s390x.ddeb a7ab17934be1f12f74615365ed3e257ebc3d59f5d8961d70a177984d1b6f8388 136934 curl_7.47.0-1ubuntu2.19_s390x.deb 26cf0de1f28032819d8ef02af1a4b792c31566cc3419a322578fa4fd5b67cfd3 3686418 libcurl3-dbg_7.47.0-1ubuntu2.19_s390x.deb 73e9de616c986c1c676661c1fca812da7f130ebce60eb2bbc1ac58aedb023994 1204 libcurl3-dbgsym_7.47.0-1ubuntu2.19_s390x.ddeb c120f594a3b776f9a14e7e543997aa96ee5177bb2e1a536138e3e401c9ffc962 1212 libcurl3-gnutls-dbgsym_7.47.0-1ubuntu2.19_s390x.ddeb a3690513e4584a91daafb115410604e0ed591de0b2aa9acde7d3d5d62b0b3c92 178744 libcurl3-gnutls_7.47.0-1ubuntu2.19_s390x.deb 7008b3efa91fc5699e19eec71889fa778e6e27877c2f5de7622f8ac2962047d8 1208 libcurl3-nss-dbgsym_7.47.0-1ubuntu2.19_s390x.ddeb 5d94ada991aa5de49e553071b5f6ffcd77e84aab1fc5bb932bacab479f586776 184836 libcurl3-nss_7.47.0-1ubuntu2.19_s390x.deb 508f2c584b22bfa6e3708a61773ff4b5683bc723dc0613b645013ae0e880931a 180610 libcurl3_7.47.0-1ubuntu2.19_s390x.deb c409bb2a2e627d632bc4ef399cc1750844c3f4065e61e199c8a1a43f76b0823b 1294 libcurl4-gnutls-dev-dbgsym_7.47.0-1ubuntu2.19_s390x.ddeb 7a7a740e37761aa22aa663f1c3430c7767421c9ec69bc175335f1d7bf485b21c 259798 libcurl4-gnutls-dev_7.47.0-1ubuntu2.19_s390x.deb 0acc3cc4f5881f5973784ef7bb4a812dab5fce131b0e5531947c88d47d80d760 1290 libcurl4-nss-dev-dbgsym_7.47.0-1ubuntu2.19_s390x.ddeb 1ba7ed12bf1581c7cd0839612c5c889ce7ddac2ab38f4611bfae8c4f0ca6eef6 267070 libcurl4-nss-dev_7.47.0-1ubuntu2.19_s390x.deb f516e2f070e2cfabe1bb09278731aef62ddf7e349af5d82affa34cbf9c06aafa 1292 libcurl4-openssl-dev-dbgsym_7.47.0-1ubuntu2.19_s390x.ddeb c5e2ee00f4a5417def972f7447182eb70d44dcfa73ad221349f890523236db54 261630 libcurl4-openssl-dev_7.47.0-1ubuntu2.19_s390x.deb Files: e96d3514a63e64249266e0bb1eaf78ef 1086 web extra curl-dbgsym_7.47.0-1ubuntu2.19_s390x.ddeb 2b153c157035c9b62179091cf445bc66 136934 web optional curl_7.47.0-1ubuntu2.19_s390x.deb 1d45d0d2bf705f56a1047dd405bbb95c 3686418 debug extra libcurl3-dbg_7.47.0-1ubuntu2.19_s390x.deb c1c1b2e3f266c8db3bee118758da2dc9 1204 libs extra libcurl3-dbgsym_7.47.0-1ubuntu2.19_s390x.ddeb e3e57203e755b750938779d94da777c9 1212 libs extra libcurl3-gnutls-dbgsym_7.47.0-1ubuntu2.19_s390x.ddeb 36d2d4a1507dec810165a609c972892a 178744 libs optional libcurl3-gnutls_7.47.0-1ubuntu2.19_s390x.deb f1767291b519a5c314a177117e0d375f 1208 libs extra libcurl3-nss-dbgsym_7.47.0-1ubuntu2.19_s390x.ddeb 3e749a76a6d125c0a39b80aacc9ff246 184836 libs optional libcurl3-nss_7.47.0-1ubuntu2.19_s390x.deb cdf5d2bee3dd6cacc9e188cd181f4b46 180610 libs optional libcurl3_7.47.0-1ubuntu2.19_s390x.deb 6c416c5d591a5722472cf83e7b4d8fa2 1294 libdevel extra libcurl4-gnutls-dev-dbgsym_7.47.0-1ubuntu2.19_s390x.ddeb c2d54d77d2eb736aba8f16959016562f 259798 libdevel optional libcurl4-gnutls-dev_7.47.0-1ubuntu2.19_s390x.deb 5dcfe7ea8a5d06fc3662c2424dffaeca 1290 libdevel extra libcurl4-nss-dev-dbgsym_7.47.0-1ubuntu2.19_s390x.ddeb 794892dd33fc632ba7244dc341cadeca 267070 libdevel optional libcurl4-nss-dev_7.47.0-1ubuntu2.19_s390x.deb cd6a07ba5f29a84fac585d45564571e7 1292 libdevel extra libcurl4-openssl-dev-dbgsym_7.47.0-1ubuntu2.19_s390x.ddeb 55c53ddfa504d74402f2794cf8cb774b 261630 libdevel optional libcurl4-openssl-dev_7.47.0-1ubuntu2.19_s390x.deb Original-Maintainer: Alessandro Ghedini