[ubuntu/artful-proposed] curl 7.55.0-1ubuntu1 (Accepted)

Gianfranco Costamagna locutusofborg at debian.org
Mon Aug 14 11:03:13 UTC 2017


curl (7.55.0-1ubuntu1) artful; urgency=low

  * Merge from Debian unstable.  Remaining changes:
    - Drop dependencies not in main:
      + Build-Depends: Drop libssh2-1-dev, and libnghttp2-dev.
      + Drop libssh2-1-dev from binary package Depends.
      + debian/control: drop --with-nghttp2

curl (7.55.0-1) unstable; urgency=medium

  * New upstream release
    - Fix TFTP sends more than buffer size as per CVE-2017-1000100
      (Closes: #871555)
    - Fix URL globbing out of bounds read as per CVE-2017-1000101
      (Closes: #871554)
  * Refresh patches and drop patches merged upstream
  * Update Standards-Version to 4.0.1 (no changes needed)
  * Drop -dbg package

Date: Mon, 14 Aug 2017 13:02:36 +0200
Changed-By: Gianfranco Costamagna <locutusofborg at debian.org>
Maintainer: Ubuntu Developers <ubuntu-devel-discuss at lists.ubuntu.com>
https://launchpad.net/ubuntu/+source/curl/7.55.0-1ubuntu1
-------------- next part --------------
-----BEGIN PGP SIGNED MESSAGE-----
Hash: SHA256

Format: 1.8
Date: Mon, 14 Aug 2017 13:02:36 +0200
Source: curl
Binary: curl libcurl3 libcurl3-gnutls libcurl3-nss libcurl4-openssl-dev libcurl4-gnutls-dev libcurl4-nss-dev libcurl4-doc
Architecture: source
Version: 7.55.0-1ubuntu1
Distribution: artful
Urgency: medium
Maintainer: Ubuntu Developers <ubuntu-devel-discuss at lists.ubuntu.com>
Changed-By: Gianfranco Costamagna <locutusofborg at debian.org>
Description:
 curl       - command line tool for transferring data with URL syntax
 libcurl3   - easy-to-use client-side URL transfer library (OpenSSL flavour)
 libcurl3-gnutls - easy-to-use client-side URL transfer library (GnuTLS flavour)
 libcurl3-nss - easy-to-use client-side URL transfer library (NSS flavour)
 libcurl4-doc - documentation for libcurl
 libcurl4-gnutls-dev - development files and documentation for libcurl (GnuTLS flavour)
 libcurl4-nss-dev - development files and documentation for libcurl (NSS flavour)
 libcurl4-openssl-dev - development files and documentation for libcurl (OpenSSL flavour)
Closes: 871554 871555
Changes:
 curl (7.55.0-1ubuntu1) artful; urgency=low
 .
   * Merge from Debian unstable.  Remaining changes:
     - Drop dependencies not in main:
       + Build-Depends: Drop libssh2-1-dev, and libnghttp2-dev.
       + Drop libssh2-1-dev from binary package Depends.
       + debian/control: drop --with-nghttp2
 .
 curl (7.55.0-1) unstable; urgency=medium
 .
   * New upstream release
     - Fix TFTP sends more than buffer size as per CVE-2017-1000100
       (Closes: #871555)
     - Fix URL globbing out of bounds read as per CVE-2017-1000101
       (Closes: #871554)
   * Refresh patches and drop patches merged upstream
   * Update Standards-Version to 4.0.1 (no changes needed)
   * Drop -dbg package
Checksums-Sha1:
 1f5b06f0650eafd21386bc1e798d6fa47f1d6f5f 2756 curl_7.55.0-1ubuntu1.dsc
 e29683d0cfd1f3ab264af27b2dea8fa0c086f1cf 3730165 curl_7.55.0.orig.tar.gz
 3fe28088976111008b0742dd0c3da3b0a8ddd5e5 30992 curl_7.55.0-1ubuntu1.debian.tar.xz
Checksums-Sha256:
 028f52ff78a29a6ebdfbe7992ceb4ac5caa6619fa8014e5dbbce7daa5a09a798 2756 curl_7.55.0-1ubuntu1.dsc
 dae1b1be34f5983e8d46917f2bdbb2335aecd0e57f777f4c32213da6a8050a80 3730165 curl_7.55.0.orig.tar.gz
 004f434dd398a661dc75a8a7f3305d87ea828ca3e6a5059c69a444207ef7411b 30992 curl_7.55.0-1ubuntu1.debian.tar.xz
Files:
 faa05a21fc279abfbf11e080621b5cf6 2756 web optional curl_7.55.0-1ubuntu1.dsc
 66b2b81489ada6a9de77bafae8dd21d8 3730165 web optional curl_7.55.0.orig.tar.gz
 b36e87670ef4aecdeafd8e17ffe17815 30992 web optional curl_7.55.0-1ubuntu1.debian.tar.xz
Original-Maintainer: Alessandro Ghedini <ghedo at debian.org>

-----BEGIN PGP SIGNATURE-----

iQIcBAEBCAAGBQJZkYNbAAoJEPNPCXROn13ZEkcP/jpVXklwHgbKBWqI3Rv/8L4P
+IoXnFGz+DFZzDT+xvFzmpFbC1TDc7fJo/1Sx06pbAJtLGE1GlxmhRvZO3xc02HP
Pp0aRETysLLHUDOHIjeYxC4IsRXmZKEJx8aH90PedYEhDOmx4QT8I9b3r52j/g8F
LSxfxY8rabvjm5XBPRP5Cm9HOF2ukS1McVg4c7f1eC/OsOGr1FWyg01NL94ypuqW
JskhIFywA/wR7Ff7RyGqPWy2PBcTQLW0cauyi+NHXMmJZYveulztUYAoTbrZXvLK
xaVL6Ae5qOpDVUBGHMrywFRlZw5aOpYvaP2zboaqoxDKuPlAz/l3jgjY6m3ZmLTF
MSZFxmdI7AsQZW6/UVqjMyMxKbt/78H+bOI5TOjUKGdGoepUBRRdn6p1CueS7ZY1
iemlSzpyfcLn26sWbHBgce/1qu5+86Qt9ue7rPDln9jFJ4hp1gv3oafiDTi8mI3f
RcwviQpVj4a6KBDpv9DPhZnACZ2v00xOub/RKhJOjKGoobkoIrEV9DcIUtyMceZO
srXdF019fgmQKT/SphNx4oPtcbNq3InOP1TBe1CNuhtfqWNbhdHlVWNq7u81KtpL
WOSP4DhdSHjesSnV/53qvdqf3hmXRPqV6XP0BDz+7FmnCKwK3SMb4dX+4F/G88L4
+8jFl0IevoKEy2UmE2P4
=pl38
-----END PGP SIGNATURE-----


More information about the Artful-changes mailing list