[ubuntu/artful-updates] curl 7.55.1-1ubuntu2.3 (Accepted)
Ubuntu Archive Robot
cjwatson+ubuntu-archive-robot at chiark.greenend.org.uk
Wed Jan 31 23:28:13 UTC 2018
curl (7.55.1-1ubuntu2.3) artful-security; urgency=medium
* SECURITY UPDATE: Out of bounds read in code handling HTTP/2
- debian/patches/CVE-2018-1000005.patch: fix incorrect
trailer buffer size in lib/http2.c.
- CVE-2018-1000005
* SECURITY UPDATE: leak authentication data
- debian/patches/CVE-2018-1000007.patch: prevent custom
authorization headers in redirects in lib/http.c,
lib/url.c, lib/urldata.h, tests/data/Makefile.in,
tests/data/test317, tests/data/test318.
- CVE-2018-1000007
* Removing test that fails to check manpage after CVE-2018-1000007.
Date: 2018-01-29 20:47:14.096010+00:00
Changed-By: leo.barbosa at canonical.com (Leonidas S. Barbosa)
Signed-By: Ubuntu Archive Robot <cjwatson+ubuntu-archive-robot at chiark.greenend.org.uk>
https://launchpad.net/ubuntu/+source/curl/7.55.1-1ubuntu2.3
-------------- next part --------------
Sorry, changesfile not available.
More information about the Artful-changes
mailing list