Format: 1.8 Date: Tue, 23 Mar 2021 09:13:58 -0400 Source: curl Binary: curl libcurl4 libcurl3-gnutls libcurl3-nss libcurl4-openssl-dev libcurl4-gnutls-dev libcurl4-nss-dev libcurl4-doc Architecture: ppc64el Version: 7.58.0-2ubuntu3.13 Distribution: bionic Urgency: medium Maintainer: Launchpad Build Daemon Changed-By: Marc Deslauriers Description: curl - command line tool for transferring data with URL syntax libcurl3-gnutls - easy-to-use client-side URL transfer library (GnuTLS flavour) libcurl3-nss - easy-to-use client-side URL transfer library (NSS flavour) libcurl4 - easy-to-use client-side URL transfer library (OpenSSL flavour) libcurl4-doc - documentation for libcurl libcurl4-gnutls-dev - development files and documentation for libcurl (GnuTLS flavour) libcurl4-nss-dev - development files and documentation for libcurl (NSS flavour) libcurl4-openssl-dev - development files and documentation for libcurl (OpenSSL flavour) Changes: curl (7.58.0-2ubuntu3.13) bionic-security; urgency=medium . * SECURITY UPDATE: data leak via referer header field - debian/patches/urlapi.patch: backport url api support in include/curl/Makefile.am, include/curl/curl.h, include/curl/urlapi.h, lib/Makefile.inc, lib/urlapi-int.h, lib/urlapi.c, lib/curl_setup_once.h, lib/url.c, lib/url.h, lib/escape.c, lib/escape.h, docs/libcurl/symbols-in-versions. - debian/libcurl*.symbols: added new symbols. - debian/patches/CVE-2021-22876.patch: strip credentials from the auto-referer header field in lib/transfer.c. - CVE-2021-22876 Checksums-Sha1: aa7c6bcff3c2372e9011bf9342d9b31a0fc874ed 147332 curl-dbgsym_7.58.0-2ubuntu3.13_ppc64el.ddeb afe36390e7c130c257da2ad476a0d794755ea2dc 11732 curl_7.58.0-2ubuntu3.13_ppc64el.buildinfo 08f38b9759021c8cbca02611a83d86e9ba5d55ec 158408 curl_7.58.0-2ubuntu3.13_ppc64el.deb ca969c983e887b0e2483c37d5cb362a7cabc6f37 1405428 libcurl3-gnutls-dbgsym_7.58.0-2ubuntu3.13_ppc64el.ddeb 52818a6d099846aa065f7aa77c5db5cb4a0d6bf0 222404 libcurl3-gnutls_7.58.0-2ubuntu3.13_ppc64el.deb 3597581e600e4dfd9cac123205134067f79a360b 1443332 libcurl3-nss-dbgsym_7.58.0-2ubuntu3.13_ppc64el.ddeb d669bc739e7366d5f926967fe5f7adcf7073e0d4 229856 libcurl3-nss_7.58.0-2ubuntu3.13_ppc64el.deb 2d5ef44af13a3a391ac74436c52cb4803ff8b764 1409264 libcurl4-dbgsym_7.58.0-2ubuntu3.13_ppc64el.ddeb 638b32081ba0feab59a1872e49dca98fed597a8f 320968 libcurl4-gnutls-dev_7.58.0-2ubuntu3.13_ppc64el.deb 6342dc9b29f138e779696211c24fb2f23d8aec18 329192 libcurl4-nss-dev_7.58.0-2ubuntu3.13_ppc64el.deb d15085b1867a828df22bcbbfbb4b875e73f212d9 318264 libcurl4-openssl-dev_7.58.0-2ubuntu3.13_ppc64el.deb ecd8ee1a2e6b9261b2115c188064f58601bbbba5 221544 libcurl4_7.58.0-2ubuntu3.13_ppc64el.deb Checksums-Sha256: 85d84b0c30d7e9cee8c883eef123b18c49ffdb8504582b860961e6066fb4e043 147332 curl-dbgsym_7.58.0-2ubuntu3.13_ppc64el.ddeb 09578c60122335e120a966eadbb34adb20df9f8eb82fec6ee74c237d11bc2cce 11732 curl_7.58.0-2ubuntu3.13_ppc64el.buildinfo b7390d7ff596397b547c12c15a3d0d2098fc11f637ce604dce5a666f4353f4a9 158408 curl_7.58.0-2ubuntu3.13_ppc64el.deb 727c8aa68b0dbef4cd63eb3c6d945c77c0ba6564be6857c5b4ff574c87bfc08c 1405428 libcurl3-gnutls-dbgsym_7.58.0-2ubuntu3.13_ppc64el.ddeb ff34fc538041833929be43890fe3d5f6039901e9d182e8e478685782c282c505 222404 libcurl3-gnutls_7.58.0-2ubuntu3.13_ppc64el.deb 8f21214602f6d84b30ab127b6b817f76ea26bbdf7c33ceed7917766264265016 1443332 libcurl3-nss-dbgsym_7.58.0-2ubuntu3.13_ppc64el.ddeb 8c438e35232162fe9e54a0b5cb98f199a41c7f9a74f94e921dc4074fe8181124 229856 libcurl3-nss_7.58.0-2ubuntu3.13_ppc64el.deb 4cd53814c96bd4da9296f14d517653f1a004781403d57357fc51d830ce8b8610 1409264 libcurl4-dbgsym_7.58.0-2ubuntu3.13_ppc64el.ddeb a9725bb1a63f99d7ea839e527f2831f84a82342de5bb31af2d8a607bc5e555c0 320968 libcurl4-gnutls-dev_7.58.0-2ubuntu3.13_ppc64el.deb a5abbc18657b7ad969423ea0d6f70a3cb207746e6bd070056a66183768d777ae 329192 libcurl4-nss-dev_7.58.0-2ubuntu3.13_ppc64el.deb 8a849eab651716086d31e453cb1339055701d679a3736831b01b47da8056cd20 318264 libcurl4-openssl-dev_7.58.0-2ubuntu3.13_ppc64el.deb d70b29e374aa67a9dff71e2b4a1d536a3f68a4fe64fa6725d144695a84b9d6d2 221544 libcurl4_7.58.0-2ubuntu3.13_ppc64el.deb Files: 35bea46b075690fb74ffd6f12bdfeeb3 147332 debug optional curl-dbgsym_7.58.0-2ubuntu3.13_ppc64el.ddeb 7974f46293e1e7c018299a4d117272a7 11732 web optional curl_7.58.0-2ubuntu3.13_ppc64el.buildinfo 66eba9cbc394c05adee53580ba18316d 158408 web optional curl_7.58.0-2ubuntu3.13_ppc64el.deb e6baeaa30748467a2796e683c90ea69c 1405428 debug optional libcurl3-gnutls-dbgsym_7.58.0-2ubuntu3.13_ppc64el.ddeb df47fa792c30379ce9473a34e0caa98e 222404 libs optional libcurl3-gnutls_7.58.0-2ubuntu3.13_ppc64el.deb 9c27b862c9bd9e5c4bf5edec5eff89ce 1443332 debug optional libcurl3-nss-dbgsym_7.58.0-2ubuntu3.13_ppc64el.ddeb aae856163944daef2aeff7dcb1710c1a 229856 libs optional libcurl3-nss_7.58.0-2ubuntu3.13_ppc64el.deb c03bb1aaa7dece664d16bb4613e223ac 1409264 debug optional libcurl4-dbgsym_7.58.0-2ubuntu3.13_ppc64el.ddeb 12379c83afefd73009c59c6629a58952 320968 libdevel optional libcurl4-gnutls-dev_7.58.0-2ubuntu3.13_ppc64el.deb a0de0033b497f8871edfc703633e536b 329192 libdevel optional libcurl4-nss-dev_7.58.0-2ubuntu3.13_ppc64el.deb aec11a07c87ca327c0a4f835ab2e4b09 318264 libdevel optional libcurl4-openssl-dev_7.58.0-2ubuntu3.13_ppc64el.deb 8eeb9f0293cf809628ce765389ca1b7f 221544 libs optional libcurl4_7.58.0-2ubuntu3.13_ppc64el.deb Original-Maintainer: Alessandro Ghedini